cs-extract-key.py is a tool designed to extract cryptographic keys from Cobalt Strike beacon process memory dumps.
This tool was already available in my beta repository.
This tool can extract cryptographic keys from process memory dumps of a version 3.x beacon directly:
And from version 4.x together with encrypted data extracted from network capture:
More details can be found in the man page, and in and upcoming blog post.
cs-extract-key_V0_0_1.zip (https)Click to Open Code Editor