{"repo":"Patrick-DE/C2-logparser","free":true,"listed":false,"github":"https://github.com/Patrick-DE/C2-logparser","clone":"git clone https://github.com/Patrick-DE/C2-logparser.git","description":"Parses logs created by Cobalt Strike, Brute Ratel, OC2 and creates an SQLite DB which can be used to create custom reports.","language":"Python","stars":31,"topics":["cobaltstrike","logs","parser","bruteratel","sqlite","c2","command-and-control","oc2"],"license":"GPL-3.0","category":"databases-storage","readme_excerpt":"C2 Log-Parser Support for Cobalt Strike, Brute Ratel and Outflank C2 (OC2) Parses C2 log files, stores them in a SQLite database, and generates CSV reports for red team engagements. Setup Usage The tool operates in three independent phases that can be combined: Phase Flag Description ------- ------ ------------- Ingest -i Parse log files and store them in a SQLite DB (requires -x ) Minimize -m Remove clutter and exclude beacons via config Report -r Generate CSV reports from the database Quick usage Full usage Examples Commands Configuration See config template.yml for a full example. The config file controls: Exclusions ( -m ) Type Matching Description ------ ---------- ------------- external CIDR range Exclude beacons by external IP internal CIDR range Exclude beacons by internal IP hostnames Regex (case-insensitive) Exclude beacons by hostname users Regex (case-insensitive) Exclude beacons by user commands Contains / and / regex Remove log entries matching patterns Redactions Sensitive data (passwords, hashes, tokens) is automatically redacted in reports based on configurable regex patterns and replacement strings. Reporting ( -r ) The following CSV reports are generated into /reports/ : Report Description -------- ------------- activity-report.csv All operator input and task entries dl-ul-report.csv File download and upload activity beacon-report.csv All valid beacons with metadata (hostname, IP, user, process, join/exit times) ioc-report.csv Indicators of compromise (file","default_branch":null,"files":null,"tree":[],"storefront":"/r/Patrick-DE","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Patrick-DE/C2-logparser/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}