Comment by A. No — Wednesday 30 March 2022 @ 11:15
I do not mind answering you questions about Cobalt Strike. But can you please post them under a related blog post or page? Having a discussion about CS under an Excel file format tool, can be very confusing for other readers.
So please post your question under a related post, for example my latest 1768.py post. And I’ll happily answer it there, and then remove this comment. Thanks.
RT @DhaeyerWolf: Amazing post by @DidierStevens. If you’re new to creating YARA rules, this is a perfect example of how versatile they are… 2 weeks ago
Sorry to ask about Cobalt Strike:
https://research.nccgroup.com/2022/03/25/mining-data-from-cobalt-strike-beacons/
Is it possible to distinguish Crooks and Red-Teams with the Trial/Lisence or the Watermark field?
The domain or the “from_IP” is the C2 Server?
$File = ‘c:\users\[user]\downloads\beacons-2022.jsonl’
$Cobalt = get-content $File | ConvertFrom-Json
$Cobalt.domains
$Cobalt.collected_from_ip
$Cobalt.org
Comment by A. No — Wednesday 30 March 2022 @ 11:15
I do not mind answering you questions about Cobalt Strike. But can you please post them under a related blog post or page? Having a discussion about CS under an Excel file format tool, can be very confusing for other readers.
So please post your question under a related post, for example my latest 1768.py post. And I’ll happily answer it there, and then remove this comment. Thanks.
Comment by Didier Stevens — Sunday 3 April 2022 @ 15:14