CS配置解析
原名:analyzing-cobaltstrike-malleable-c2-profiles
解析分析Cobalt Strike Malleable C2配置文件,提取HTTP/DNS变换、URI、头部、睡眠/抖动及注入行为,生成网络检测签名。适用于逆向分析捕获的配置文件或构建针对Cobalt Strike Beacon流量的检测规则。
- 分类
- 学习研究
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-25
- TRACE 评分
- 3 / 5
内容概览
Cobalt Strike Malleable C2 profiles are domain-specific language scripts that customize how Beacon communicates with the team server, defining HTTP request/response transformations, sleep intervals, jitter values, user agents, URI paths, and process injection behavior. Threat actors use malleable profiles to disguise C2 traffic as legitimate services (Amazon, Google, Slack). Analyzing these profiles reveals network indicators for detection: URI patterns, HTTP headers, POST/GET transforms, DNS settings, and process injection techniques. The dissect.cobaltstrike library can parse both profile files and extract configurations from beacon payloads, while pyMalleableC2 provides AST-based parsing using Lark grammar for programmatic profile manipulation and validation. - When investigating security incidents that require analyzing cobaltstrike malleable c2 profiles - When building detection rul…