logo

Cobalt Strike - Bypassing C2 Network Detections

ID: f38f1889-2689-52ae-a912-5f595e04cdf3

STIX ID: report--f38f1889-2689-52ae-a912-5f595e04cdf3

Feed Name: On the Hunt

Threat Score
65/100

Date Published: 2021-03-03

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This blog post demonstrates how to evade network-based detections for Cobalt Strike beacons by using the C2 Concealer tool to generate custom Malleable C2 profiles (including certificate choices) and shows a brief test where a custom profile allowed a C2 connection to bypass Symantec Endpoint Protection that blocked the default profile.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.