> For the complete documentation index, see [llms.txt](https://codex-7.gitbook.io/codexs-terminal-window/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike.md).

# Detecting Cobalt Strike

Stuff that causes Cobalt Strike to be flagged, so we don't accidentally burn ourselves.
