logo

The Complete Guide to Hunting Cobalt Strike - Part 3: Automated C2 Infrastructure Discovery

ID: a6355794-1067-5220-90ba-fdb4d9034d99

STIX ID: report--a6355794-1067-5220-90ba-fdb4d9034d99

Feed Name: Hunt.io Blog

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

Hunt.io demonstrates automated detection and pivoting to uncover large-scale, persistent Cobalt Strike C2 infrastructure—reporting thousands of detections and detailed pivots (mail.live.com certificate CNs, an X.509 hash, and a Redacted Headers SHA256) with example HuntSQL queries, IOC listings (multiple IPs/ASNs), and practical mitigation guidance for network and endpoint defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.