Apr4h / CobaltStrikeScan

Scan files or process memory for CobaltStrike beacons and parse their configuration
MIT License
893 stars 114 forks source link

Feature new Yara rules #17

Open conexioninversa opened 1 year ago

conexioninversa commented 1 year ago

Great tool. It would be nice to include the following Google Yara rules in: https://github.com/chronicle/GCTI/tree/main/YARA