logo

The Complete Guide to Hunting Cobalt Strike - Part 2: 10+ HuntSQL Recipes to Find Cobalt Strike

ID: 5ddd49f8-ff59-5ac6-9b99-734d78aaab73

STIX ID: report--5ddd49f8-ff59-5ac6-9b99-734d78aaab73

Feed Name: Hunt.io Blog

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This Hunt.io guide presents 10+ HuntSQL™ recipes to detect, cluster, and track Cobalt Strike C2 infrastructure: it explains the enriched malware dataset fields (watermark, public_key, submit_uri, user_agent, sleeptime, spawn targets), provides concrete queries and example results (including statistics on ports, ASNs, and watermark prevalence), and demonstrates a profile-based hunt tied to a Lazarus-style Cobalt Strike configuration to help threat hunters map and prioritize active Cobalt Strike activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.