logo

Using Cobalt Strike to Find (More) Cobalt Strike

ID: f3ea845a-517f-591f-92c5-919a5c026905

STIX ID: report--f3ea845a-517f-591f-92c5-919a5c026905

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2025-12-01

Date Updated: 2026-04-27

Author: Mark Ellzey; Senior Security Researcher

...
...

This report demonstrates how to discover and expand known Cobalt Strike command-and-control infrastructure by analyzing TLS certificate Distinguished Names, certificate ordering quirks produced by Cobalt Strike, Certificate Transparency logs, and Censys scan data; it includes scripts, sample DN fingerprints, case studies of active C2 servers (including some using legitimate CA certs), and recommended hunting queries to surface additional suspected hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.