logo

Hunting and Detecting Cobalt Strike: The Full Guide

ID: e69b9cb6-9b6b-5745-869f-07cdd9bfb8b8

STIX ID: report--e69b9cb6-9b6b-5745-869f-07cdd9bfb8b8

Feed Name: Sekoia.com

Threat Score
80/100

Date Published: 2021-03-24

Date Updated: 2026-07-20

...
...

This Sekoia Threat & Detection Lab blog analyzes the widespread malicious use of Cobalt Strike — its client/server architecture, beacon types and Malleable C2 profiles — and provides practical detection and hunting guidance (default SSL certificates, HTTP response quirks, DNS beacon labels, named pipe patterns, default payload names), SIEM rule examples, and mitigation recommendations including real-time detection, memory forensics, EDR/Yara usage, and hardening of PowerShell and Office macro policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.