Skip to content

Conversation

@DidierStevens
Copy link

I added a probe to detect Cobalt Strike's administrative interface.
It runs by default on port 50050 and is over TLS.
The probe is a set of bytes to authenticate with an invalid password: 255 NULL bytes.
The reply should be 4 NULL bytes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant