Ross ROSS = Recommend OSS · open-source software intelligence for agents

MichaelKoczwara/Awesome-CobaltStrike-Defence resource

Defences against Cobalt Strike observed · 2026-08-28

github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2070
  • days_rel: n/a
  • days_push: 1511
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1301 stars · 193 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A curated awesome-list of defensive resources, tools, and detection techniques for countering Cobalt Strike, a commercial adversary simulation and post-exploitation framework. It aggregates hunting tools, Yara rules, beacon configuration parsers, JARM fingerprinting resources, and MITRE ATT&CK references.

Use cases

  • find tools to detect cobalt strike beacons on my network
  • learn how to defend against cobalt strike attacks
  • hunt for sleeping beacons in memory
  • parse cobalt strike beacon configurations
  • find yara rules for detecting cobalt strike malware
  • build a threat hunting playbook for C2 traffic

When to choose

  • you are a blue teamer or incident responder investigating suspected Cobalt Strike activity
  • you need a starting point for building detection and hunting capabilities against C2 frameworks
  • you want a curated index of beacon scanning, Yara, and forensic tools

When to avoid

  • you want an offensive tool or a way to run Cobalt Strike itself
  • you need a single maintained detection product rather than a list of links
  • you are defending against C2 frameworks other than Cobalt Strike

Facets

learning-resource · maturity maintenance

security vulnerability-scanning monitoring developer-tools security penetration-testing awesome-lists developer-tools cross-platform awesome-list cobalt-strike threat-detection incident-response dfir c2-detection yara-rules threat-hunting

1 source

Member repositories

RepositoryRoleHealth v2
MichaelKoczwara/Awesome-CobaltStrike-Defencemain32

For agents

markdown · JSON · MCP: product_card(name="MichaelKoczwara/Awesome-CobaltStrike-Defence")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem