cobaltstrike-detection topic

List cobaltstrike-detection repositories

ETWProcessMon2

283
Stars
67
Forks
Watchers

ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.

cs-discovery

19
Stars
4
Forks
Watchers

Detecting Cobalt Strike Team Servers on targets through traffic telemetry.