Collecting Cobalt Strike Beacons with the Elastic Stack
ID: a77f977d-0746-5b93-82a1-f4e2d99dfc85
STIX ID: report--a77f977d-0746-5b93-82a1-f4e2d99dfc85
Feed Name: Elastic Security Labs
Threat Score
This Elastic blog explains how to configure Elastic Fleet and the Endpoint Security integration to collect Cobalt Strike beacon payloads from Windows memory, locate relevant telemetry in Kibana, decode Base64+zlib compressed memory-region artifacts (for example using CyberChef), and obtain Portable Executable files for analysis; it focuses on collection and analysis workflow rather than detailing a specific incident or actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
