logo

Collecting Cobalt Strike Beacons with the Elastic Stack

ID: a77f977d-0746-5b93-82a1-f4e2d99dfc85

STIX ID: report--a77f977d-0746-5b93-82a1-f4e2d99dfc85

Feed Name: Elastic Security Labs

Threat Score
60/100

Date Published: 2022-06-01

Date Updated: 2026-04-27

...
...

This Elastic blog explains how to configure Elastic Fleet and the Endpoint Security integration to collect Cobalt Strike beacon payloads from Windows memory, locate relevant telemetry in Kibana, decode Base64+zlib compressed memory-region artifacts (for example using CyberChef), and obtain Portable Executable files for analysis; it focuses on collection and analysis workflow rather than detailing a specific incident or actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.