CobaltStrikeForensic

Malware analyzer

Toolset to analyze and research malware and Cobalt Strike beacon behavior

Toolset for research malware and Cobalt Strike beacons

GitHub

206 stars
11 watching
38 forks
Language: HTML
last commit: over 3 years ago

Related projects:

RepositoryDescriptionStars
eremit4/cs-discoveryDetects malicious servers in network traffic by analyzing encoded byte patterns20
strozfriedberg/cobaltstrike-config-extractorA toolset to extract and analyze configurations from malware samples known as Cobalt Strike Beacons.148
wikiz/service_cobaltstrikeA CobaltStrike profile repository containing metadata and information about the CobaltStrike malware39
b1tg/cobaltstrike-beacon-rustA Cobalt Strike beacon implementation in Rust for creating malicious network connections180
te-k/cobaltstrikeDetects and analyzes Cobalt Strike beacons by analyzing HTTP responses and extracting configuration information.266
huoji120/cobaltstrikedetectedDetects potential Cobalt Strike malware by analyzing memory allocation patterns during code execution272
sentinel-one/cobaltstrikeparserDeciphers CobaltStrike Beacon configurations from various formats.1,028
mgeeky/cobalt-arsenalA collection of battle-tested PowerShell scripts for Cobalt Strike 4.0+1,048
deepingh0st/erebusA Cobalt Strike plugin for post-exploitation and privilege escalation tests1,494
timwhitez/cobalt-strike-aggressor-scriptsA Cobalt Strike plugin package with various exploit and password cracking tools.672
lintstar/cs-serverchanAutomates CobaltStrike notification to WeChat via ServerChan93
r1is/cobalt_strike_botAutomates CobaltStrike login notifications to Slack and Feishu.88
fox-it/dissect.cobaltstrikeLibrary for dissecting and parsing data related to Cobalt Strike exploits148
wafinfo/cobaltstrikeA plugin for Cobalt Strike that automates various tasks such as domain lookup, information gathering, and internal network scanning.179
1135/1135-cobaltstrike-toolkitProvides tools and configurations for a Cobalt Strike toolkit to support advanced persistent threat (APT) operations149