Threat intelligence feed

Cobalt Strike IOC Feed

Detection of Cobalt Strike is often the last warning before ransomware. PrecisionSec's curated Cobalt Strike feed tracks active Beacon C2 infrastructure in real time.

15-day free trial · no credit card · reply within one business day

Drops straight into the tools your SOC already runs

What is Cobalt Strike?

Cobalt Strike is a commercial adversary-simulation and post-exploitation framework. Legitimately used by red teams, it is also one of the most heavily abused tools in real intrusions. Its Beacon implant gives attackers command and control, lateral movement and payload delivery.

Cobalt Strike Beacon C2 overview from the PrecisionSec feed

Detect active Beacon C2 before ransomware

Finding Cobalt Strike on your network is frequently the final indicator before a ransomware deployment, which makes early, high-confidence detection of active Beacon infrastructure so valuable.

Automated Cobalt Strike alerting from the PrecisionSec feed

Why track it with PrecisionSec

Catch intrusions earlier

Beacon C2 often appears days before encryption. Blocking it buys your team time to respond before ransomware deploys.

High-confidence, curated indicators

We extract C2 servers and config (watermarks and profiles) from live samples, verified to cut false positives.

Built for your stack

Beacon C2 and distribution indicators are delivered in the formats your existing security tools already speak.

Cobalt Strike intelligence is delivered via STIX/TAXII, MISP, CSV and REST API. See all integrations. Cobalt Strike C2 and distribution IOCs are included in every PrecisionSec intelligence subscription.

Recent Cobalt Strike IOCs

Live Cobalt Strike command & control (C2) indicators, pulled straight from our threat feed and refreshed as fast as every minute. For full coverage and API delivery, sign up for a free trial.

Live feedUpdated 41s ago
First seenIndicatorTypeConfidence
3msecure-update-cdn[.]netC2 domainHigh
9m91.213.50[.]114C2 IPHigh
15mapi-telemetry-sync[.]com/loadPayload URLHigh
22mb7e2f48c…3d90afSHA256 HashMedium
38mnode-relay-7f1c[.]orgC2 domainHigh
Live Cobalt Strike indicators, surfaced and verified the moment they appear. Shown defanged — the ↗ icon opens the full record in Indicator Search, free. Raw, real-time data via the REST API or a free trial.

Ready to see all of our data?

Start your 15-day free trial and get the full Cobalt Strike feed, plus every other malware and C2 feed.

Request a 15-day trial