analyzing-cobaltstrike-malleable-c2-profiles

Community

Decode malleable C2 profiles into actionable IOCs.

AuthorYukiIto1999
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill helps security teams quickly analyze Cobalt Strike Malleable C2 profiles to extract configurations, indicators, and actionable detection guidance.

Core Features & Use Cases

  • Parse Malleable C2 profiles via dissect.cobaltstrike or pyMalleableC2 to extract user agents, URIs, sleep/jitter, headers, and injection settings.
  • Generate detection indicators and potential Suricata/ Snort rules to aid in security monitoring.
  • Support threat hunting and incident response workflows by producing structured findings with IOCs and recommended mitigations.

Quick Start

Run the analyzer on a Malleable C2 profile to generate a structured findings report.

Dependency Matrix

Required Modules

dissect.cobaltstrikepyMalleableC2

Components

scriptsreferences

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: analyzing-cobaltstrike-malleable-c2-profiles
Download link: https://github.com/YukiIto1999/ctf-sleuth/archive/main.zip#analyzing-cobaltstrike-malleable-c2-profiles

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.