This new version of 1768.py, my tool to analyze Cobalt Stike beacons, has fixes, support for more encodings, and an option to output the config in JSON format.

MD5: EB9C949BB7B5DD3EF9ECEBF7F3C21184
SHA256: 3EC0BB7B41CC5C0E1534F09BAE67D62B220F8D83A7F02EC0F856F8741F86EB31
[…] Update: 1768.py Version 0.0.6 […]
Pingback by Week 21 – 2021 – This Week In 4n6 — Sunday 23 May 2021 @ 8:45
[…] Tools: 1768.py. […]
Pingback by Making Sense Of Encrypted Cobalt Strike Traffic – Didier Stevens Videos — Wednesday 26 May 2021 @ 20:10
[…] Tools: cs-dns-stager.py, base64dump.py and 1768.py […]
Pingback by Cobalt Strike & DNS – Part 1 – Didier Stevens Videos — Sunday 30 May 2021 @ 18:38