Closed MarcOverIP closed 1 year ago
The main difference is that CS starts with c2.log.type=beacon instead of implant like Stage1. Because of some incorrect logstash filtering of Cobalt Strike logs, for every log that starts with [note]
the value of c.2.log.type stays beacon
Frankly, this is good enough. Closing this issue now.
events (becomes one of)
implant (becomes one of)
events (becomes one of)
beacon (becomes one of)
screenshots (stays the same) keystrokes (stays the same) downloads (stays the same) credentials (stays the same)
events (becomes one of)
Check if terms used in c2.log.type are consistent across multiple C2 frameworks. Especially pay attention to beacon, implant_input and implant_task