CobaltStrikeDetected

Memory malware detector

Detects potential Cobalt Strike malware by analyzing memory allocation patterns during code execution

40行代码检测到大部分CobaltStrike的shellcode

GitHub

272 stars
8 watching
48 forks
Language: C++
last commit: about 5 years ago

Related projects:

RepositoryDescriptionStars
huoji120/duckmemoryscanA tool to detect memory-based evasion techniques used in malware and rootkits711
eremit4/cs-discoveryDetects malicious servers in network traffic by analyzing encoded byte patterns20
romanemelyanov/cobaltstrikeforensicToolset to analyze and research malware and Cobalt Strike beacon behavior206
wikiz/service_cobaltstrikeA CobaltStrike profile repository containing metadata and information about the CobaltStrike malware39
te-k/cobaltstrikeDetects and analyzes Cobalt Strike beacons by analyzing HTTP responses and extracting configuration information.266
lintstar/cs-serverchanAutomates CobaltStrike notification to WeChat via ServerChan93
b1tg/cobaltstrike-beacon-rustA Cobalt Strike beacon implementation in Rust for creating malicious network connections180
fox-it/dissect.cobaltstrikeLibrary for dissecting and parsing data related to Cobalt Strike exploits148
deepingh0st/erebusA Cobalt Strike plugin for post-exploitation and privilege escalation tests1,494
liaorj/cs_fakesubmitA script to simulate a Cobaltstrike connection130
r1is/cobalt_strike_botAutomates CobaltStrike login notifications to Slack and Feishu.88
ydhcui/csload.netA tool designed to bypass common anti-malware measures by loading malicious Cobalt Strike shellcodes into infected systems.121
snowming04/cobaltstrike4.0_relatedA collection of resources and documentation for Cobalt Strike 4.0398
strozfriedberg/cobaltstrike-config-extractorA toolset to extract and analyze configurations from malware samples known as Cobalt Strike Beacons.148
phink-team/cobaltstrike-ms17-010Exploits and tools for the MS17-010 vulnerability in Windows 7 x64 and Windows Server 2008 R2418