Apr4h / CobaltStrikeScan

Scan files or process memory for CobaltStrike beacons and parse their configuration
MIT License
893 stars 114 forks source link

changed YARA signatures to Neo23x0/signature-base. Beacon config sect… #13

Closed Apr4h closed 3 years ago

Apr4h commented 3 years ago

…ion now decoded based on detected YARA signature.