New
CobaltStrikeScan v.1.1.1
New Features
- Users can choose to scan ALL (x64) running processes for Cobalt Strike beacons instead of just injected threads
- '-d' option allows scanning of all dump files in a directory for Cobalt Strike beacons
- Added support for scanning of large dump files (> 2GB) e.g. RAM captures. (won't output process information)
- Added ability to detect and parse non-encoded configuration sections (usually found when trial versions of Cobalt Strike are used)
Bug Fixes
- Scanning a dump file would only parse and output the first beacon detection.
- Stopped outputting multiple instances of the same beacon from a single process/file
