Analyzing Cobaltstrike Malleable C2 Profiles

Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/analyzing-cobaltstrike-malleable-c2-profiles commit b0c0e1b9a7

Frequently asked questions

npx skillmds@latest add gabrielmoreira/analyzing-cobaltstrike-malleable-c2-profiles