analyzing-cobaltstrike-malleable-c2-profiles
Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.
Source facts
- Repository
- mukul975/Anthropic-Cybersecurity-Skills
- Last source activity
- August 2, 2026 at 16:32
- Detected SKILL.md language
- English
- Stars
- 33,129
- Forks
- 4,016
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.
Showing SKILL.md
- name
- analyzing-cobaltstrike-malleable-c2-profiles
- description
- Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.
- domain
- cybersecurity
- subdomain
- malware-analysis
- tags
- ["cobalt-strike","malleable-c2","c2-detection","beacon-analysis","network-signatures","threat-hunting","red-team-tools"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- nist_csf
- ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"]
- mitre_attack
- ["T1071.001","T1573.002","T1001.003","T1090.004","T1102"]