YARA rule 'c2_framework_indicators': Command-and-control framework indicators (Cobalt Strike, Metasploit, Sliver, etc.) [malware]
Critical
- Category
- YARA Match
- Content
# Pentest C2 Operator Tools | Tool | URL | |---|---| | Sliver | https://github.com/BishopFox/sliver | | Mythic | https://github.com/its-a-feature/Mythic | | Havoc | https://github.com/HavocFramework/Havoc | | Cobalt Strike | https://www.cobaltstrike.com/ | | Atomic Red Team | https://github.com/redcanaryco/atomic-red-team |
- Confidence
- 85% confidence
- Finding
- YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
