Siber Alem / Detail / 261 / Cobalt-strike-beacon-shellcode-anatomisi-ve-forensic-tespiti
vuln_report_viewer.sh
VULN REPORT / shellcode / ID: 261

Cobalt Strike Beacon Shellcode Anatomisi ve Forensic Tespiti

2026-07-21
1 views
Verified
Windows/linux x64

Summary

This entry details a vulnerability found in the target system. The exploit was published on 2026-07-21 and has garnered 1 views from the community. It is classified under the shellcode category. Users are advised to review the source code in the Detail tab for technical specifics.

exploit_261.txt

Modern C2 - Cobalt Strike - Beacon Anatomisi

Cobalt Strike Beacon: Shellcode Anatomisi ve Forensic Tespit

Cobalt Strike, endustri standardi red team C2 platformudur. Beacon shellcode tabanli implant; HTTP/S, DNS, SMB kanallar uzerinden C2 ile iletisir.

Beacon Bellek Yapisi

[Beacon reflective loader] PE header ayristiricisi .data bolumu - Encrypted Config (XOR 0x69) sleep_mask obfuskasyon (CS 4.x+) Beacon dongusu baslar: sleep(jitter) -> C2 poll Gorev al -> Calistir -> Sonuc gonder Config icerigi: C2 server IP/domain Sleep time + jitter HTTP User-Agent, URI AMSI/ETW bypass secenekleri

Volatility ile Tespit

vol -f mem.dmp windows.malfind | grep -A5 MZ pip install maldump && maldump mem.dmp -o output/ BeaconEye.exe -pid 1234 python3 1768.py beacon.bin # config coz

Iz Birakma Noktalari

Bellekte aranacaklar: - MZ header + reflective loader - XOR key 0x69 pattern (klasik config sifrelemesi) - Non-image RWX bolgeler (malfind ciktisi) - Named pipe: pipe\MSSE-

MDE Microsoft Defender

Defender for Endpoint, Beacon config sifre cozme desenlerini ve sleep_mask obfuskasyon pattern'lerini tespit eder.

Author Profile

Krun!x
Krun!x Elite Member
View All Submissions

Entry Stats

Views 1
Downloads 0
Comments 0