网络安全 Analyzing Cobaltstrike Malleable C2 Profiles

Model: minimax-m3 | ¥0.20/call
网络安全Claude Opus 4.7安全审计AnalyzingMalleable

Analyzing Cobaltstrike Malleable C2 Profiles:网络安全 skill: analyzing-cobaltstrike-malleable-c2-pr,适用于安全分析、取证与威胁排查场景。

Calls: 1

Skill Documentation

网络安全 Analyzing Cobaltstrike Malleable C2 Profiles

摘要

Analyzing Cobaltstrike Malleable C2 Profiles:网络安全 skill: analyzing-cobaltstrike-malleable-c2-pr,适用于安全分析、取证与威胁排查场景。

> 来源: mukul975/Anthropic-Cybersecurity-Skills (18k stars) — 网络安全专业技能集

> 原文件: skills/analyzing-cobaltstrike-malleable-c2-profiles/SKILL.md

> 模型推荐: claude-opus-4-7 (安全分析深度推理)

这个 skill 是干嘛的

mukul975 整理的 100+ 个网络安全专业 skill,覆盖渗透测试 / 取证 / 威胁情报 / 合规审计 / 云安全 / 移动安全 等领域。每个 skill 对应一个具体的安全分析任务。

michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。

---

🤖 Agent 使用说明

1. 用户提到"分析 X 日志 / 取证 / 检测威胁 / 渗透测试 / 安全审计"时,触发对应 skill

2. skill 会按操作步骤一步步执行(取证镜像 / 解析日志 / 跑威胁情报 / etc.)

3. 涉及破坏性操作(rm/drop/format)前必须 ask user 确认

4. 完工后让 Agent 跑自检 step

5. 如果用户要求做"防御性分析" — 区分恶意代码审计 vs 渗透测试

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 如果需要提供文件/镜像/日志/哈希,按 Agent 提示提供

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

原 skill 内容(mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-cobaltstrike-malleable-c2-profiles/SKILL.md,截断到 12k chars)

---

name: analyzing-cobaltstrike-malleable-c2-profiles

description: Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.

domain: cybersecurity

subdomain: malware-analysis

tags:

version: '1.0'

author: mahipal

license: Apache-2.0

nist_csf:

mitre_attack:

---

Analyzing CobaltStrike Malleable C2 Profiles

Overview

Cobalt Strike Malleable C2 profiles are domain-specific language scripts that customize how Beacon communicates with the team server, defining HTTP request/response transformations, sleep intervals, jitter values, user agents, URI paths, and process injection behavior. Threat actors use malleable profiles to disguise C2 traffic as legitimate services (Amazon, Google, Slack). Analyzing these profiles reveals network indicators for detection: URI patterns, HTTP headers, POST/GET transforms, DNS settings, and process injection techniques. The `dissect.cobaltstrike` library can parse both profile files and extract configurations from beacon payloads, while `pyMalleableC2` provides AST-based parsing using Lark grammar for programmatic profile manipulation and validation.

When to Use

Prerequisites

Steps

1. Install libraries: `pip install dissect.cobaltstrike` or `pip install pyMalleableC2`

2. Parse profile with `C2Profile.from_path("profile.profile")`

3. Extract HTTP GET/POST block configurations (URIs, headers, parameters)

4. Identify user agent strings and spoof targets

5. Extract sleep time, jitter percentage, and DNS beacon settings

6. Analyze process injection settings (spawn-to, allocation technique)

7. Generate Suricata/Snort signatures from extracted network indicators

8. Compare profile against known threat actor profile collections

9. Extract staging URIs and payload delivery mechanisms

10. Produce detection report with IOCs and recommended network signatures

Expected Output

A JSON report containing extracted C2 URIs, HTTP headers, user agents, sleep/jitter settings, process injection config, spawned process paths, DNS settings, and generated Suricata-compatible detection rules.

常见问题(FAQ)

使用「Analyzing Coba」这个 skill 能解决什么问题?

本 skill 专注于Analyzing Coba,网络安全 skill: analyzing-cobaltstrike-malleable-c2-profiles。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Analyzing Coba」?

当你需要在Analyzing Cobaltstrike Malleable C2 Profiles相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Analyzing Coba」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。

FAQ

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 如果需要提供文件/镜像/日志/哈希,按 Agent 提示提供

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

使用「Analyzing Coba」这个 skill 能解决什么问题?

本 skill 专注于Analyzing Coba,网络安全 skill: analyzing-cobaltstrike-malleable-c2-profiles。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Analyzing Coba」?

当你需要在Analyzing Cobaltstrike Malleable C2 Profiles相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Analyzing Coba」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。