RULE(RULE ID:339064)

Rule General Information
Release Date: 2025-06-10
Rule Name: Cobalt Strike Shellcode Download (x32) Detection
Severity:
CVE ID:
Rule Protection Details
Description: Cobalt Strike is a professional penetration test and red team operation tool with powerful command and control (C2) capabilities and rich post-penetration modules for port forwarding, service scanning, automated overflow, multi-mode port listening and more. This rule detects Cobalt Strike Shellcode communication behavior.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.