MiTM Cobalt Strike Network Traffic
2021-12-11 19:14:58 Author: blog.didierstevens.com(查看原文) 阅读量:30 收藏

MiTM Cobalt Strike Network Traffic

I made a small PoC. cs-mitm. py is a mitmproxy script that intercepts Cobalt Strike traffic, decrypts it and injects its own commands. In this video, a malicious beacon is terminated by sending it an exit command. I selected a malicious beacon that uses one of the leaked private keys.

The script does not support data transforms, but that can be easily added, for example with code found in cs-parse-traffic.py.

No comments yet.


文章来源: https://blog.didierstevens.com/2021/12/11/mitm-cobalt-strike-network-traffic/
如有侵权请联系:admin#unsafe.sh