> For the complete documentation index, see [llms.txt](https://blog.securehat.co.uk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://blog.securehat.co.uk/cobaltstrike.md).

# CobaltStrike

- [Cobalt Strike Staging and Extracting Configuration Information](https://blog.securehat.co.uk/cobaltstrike/extracting-config-from-cobaltstrike-stager-shellcode.md): This post covers how Cobalt Strike staging works, how to replicate a staging request to obtain beacon shellcode, and then how to extract the Cobalt Strike config from the shellcode.
- [Fighting Back Against Cobalt Strike - Detection Ideas](https://blog.securehat.co.uk/cobaltstrike/fighting-back-against-cobalt-strike-detection-ideas.md)
