Hunting for Cobalt Strike in PCAP

#Cobalt Strike #CobaltStrike #Triage #JA3 #a0e9f5d64349fb13191bc781f81f42e1 #ThreatFox #CapLoader

In this video I analyze a pcap file with network traffic from Cobalt Strike Beacon using CapLoader. The pcap file and Cobalt Strike malware config can be downloaded from Recorded Future's Triage sandbox. Cobalt Strike Beacon configs can also be extracted locally with help of Didier Stevens' 1768.py[...]

Read the full writeup in the blog post Hunting for Cobalt Strike in PCAP