Topic: "cobaltstrike-detection"
DamonMohammadbagher/ETWProcessMon2
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Language: C# - Size: 35 MB - Last synced at: 25 days ago - Pushed at: about 1 year ago - Stars: 300 - Forks: 69

eremit4/cs-discovery
Detecting Cobalt Strike Team Servers on targets through traffic telemetry.
Language: Python - Size: 25.9 MB - Last synced at: 9 months ago - Pushed at: 9 months ago - Stars: 19 - Forks: 3
