> For the complete documentation index, see [llms.txt](https://codex-7.gitbook.io/codexs-terminal-window/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike.md).

# Detecting Cobalt Strike

- [Sleep Mask Kit IOCs](https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/sleep-mask-kit-iocs.md): YARA rule included!
- [Hunting Beacon in the heap](https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/hunting-beacon-in-the-heap.md): WORK IN PROGRESS
- [Decrypting C2 traffic with known key](https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/decrypting-c2-traffic-with-known-key.md): Reference: https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/
