Topic: "cobaltstrike-detection"
DamonMohammadbagher/ETWProcessMon2
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Language: C# - Size: 35 MB - Last synced at: about 1 month ago - Pushed at: over 1 year ago - Stars: 301 - Forks: 70

eremit4/cs-discovery
Detecting Cobalt Strike Team Servers on targets through traffic telemetry.
Language: Python - Size: 25.9 MB - Last synced at: 10 months ago - Pushed at: 10 months ago - Stars: 19 - Forks: 3
