Vincent Yiu (@vysecurity)
https://vincentyiu.co.uk/cobaltsplunk/
CobaltSplunk is a Splunk Application that knows how to 1) ingest Cobalt Strike related logs and parse them properly, 2) display useful operational dashboards, 3) display relevant reports.
- Download Cobalt.spl
- Install as application
- Ingest logs
- View the dashboard and reports as you see fit