Homemade aggressor scripts kit for Cobalt Strike
The following table illustrates all the CNA files included in this project:
Section | Name | Description |
---|---|---|
Alert | slack-alerts_linux.cna | Slack CNA file for Linux CS client |
Alert | slack-alerts_windows.cna | Slack CNA file for Windows CS client |
Alert | discord-alerts_linux.cna | Discord CNA file for Linux CS Client |
Alert | teams-alerts_linux.cna | Teams CNA file for Linux CS Client |
Alert | mattermost-alerts_linux.cna | Mattermost CNA file for Linux CS Client |
Alert | mattermost-alerts_windows.cna | Mattermost CNA file for Windows CS Client |
These CNA files will notify you via the Slack
/Discord
/Teams
/Mattermost
applications when:
- A new client connects to the team server.
- A CS client disconnects from the team server.
- A new incoming beacon.
- A new web hit occurs.
- A CS client posts something in the event log.
- New site hosts.
- New credentials come in from keylogging.
- A new screenshot is taken from Cobalt Strike.
ℹ️ Some CNA files are compatible with both Windows and Linux operating systems.
The following table illustrates the CNA files included in the Alert section:
Name | OS | App | Description |
---|---|---|---|
slack-alerts_linux.cna | Linux | Slack | Slack CNA file for Linux CS client |
slack-alerts_windows.cna | Windows | Slack | Slack CNA file for Windows CS client |
discord-alerts_linux.cna | Linux | Discord | Discord CNA file for Linux CS Client |
teams-alerts_linux.cna | Linux | Teams | Teams CNA file for Linux CS Client |
mattermost-alerts_linux.cna | Linux | Mattermost | Mattermost CNA file for Linux CS Client |
mattermost-alerts_windows.cna | Windows | Mattermost | Mattermost CNA file for Windows CS Client |
ℹ️ To set up a Slack server and webhook, you can follow these guides provided on the Slack website.
ℹ️ To set up a Discord server and webhook, you can follow these guides provided on the Discord website.
ℹ️ To set up a Microsoft Teams webhook, you can follow these guides provided on Microsoft website.
ℹ️ To set up a Mattermost webhook, you can follow these guides provided on Mattermost website.