This is an update of my tool to analyze Cobalt Strike beacons.
Option -l can be used to generate YARA rules to search for Cobalt Strike beacons with a given license ID.
1768_v0_0_4.zip (https)
MD5: 35779393F2DC6171731446F8E0AC361B
SHA256: 59148C2DA13BE4DB203F9444E837911476BDE74E41E5A82C865E9729101336D2
[…] Update: 1768.py Version 0.0.4 […]
Pingback by Week 52 – 2020 – This Week In 4n6 — Sunday 27 December 2020 @ 5:26
Have you seen: https://www.randhome.io/blog/2020/12/20/analyzing-cobalt-strike-for-fun-and-profit/
Comment by Anonym — Sunday 27 December 2020 @ 9:18
Thanks for the heads up
Comment by Didier Stevens — Monday 28 December 2020 @ 9:11