Skip to content

cobalt_sync v2.0.0

Choose a tag to compare

@chrismaddalena chrismaddalena released this 20 Sep 17:07
· 20 commits to main since this release
f136eb8

Summary

This release significantly changes how cobalt_sync works to make it better, more reliable, and compatible with Ghostwriter v4.0.0 and later.

CHANGELOG

[2.0.0] - 20 September 2023

Added

  • Added cobalt_parser, a golang program to parse and monitor Cobalt Strike logs and ship parsed events to a web server
  • Added cobalt_web, a Python web server that accepts cobalt events and posts them to Ghostwriter's v4 GraphQL endpoint
  • Added a Redis service container that functions a database to store hashes of Cobalt Strike messages to prevent duplicates

Changed

  • cobalt_sync now syncs activities via Ghostwriter's GraphQL API

Removed

  • Removed use of the legacy Ghostwriter REST API (removed in Ghostwriter v4)