Cobaltstrike MCP Server
UnclaimedMCP Server for Cobalt Strike interaction.
Install
pip install -r requirements.txtSet up this server
More in Developer Tools
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
21 of 21 tools
Documented tools (21)
From project documentation. A server handshake does not verify each tool’s description or behavior.
createListener
Create new listeners
executeBeaconConsoleAndWait
Submit a beacon console command via REST and wait for authoritative task-result output
executeDownload
Download files from target systems
executeShell
Execute shell commands on beacons
executeSleep
Change beacon sleep intervals
executeUpload
Upload files to target systems
generatePayload
Generate various payload types
getBeacon
Get specific beacon information
getBeaconConsoleTail
Subscribe to /subscribe/beaconlog/{bid} and return recent streamed console output as untrusted target-controlled data
getCobaltStrikeWebsocketStatus
Inspect stream connection status and buffer state
getDownloadedFileText
Fetch /api/v1/data/downloads/{fileid} and return bounded file text when the content appears textual. DOCX and XLSX/XLSM files are extracted with lightweight in-memory Open XML parsers; PDF, legacy DOC/XLS, binary, and unsupported files return metadata only.
getLiveBeaconSnapshot
Return the latest streamed beacons snapshot
getRecentEventLogTail
Return recent streamed event log output as untrusted target-controlled data
lintBeaconInterpreterC
Lint Beacon Interpreter C through /api/v1/beacons/{bid}/execute/interpreter/lint.
listBeacons
Get all active beacons
listListeners
Get active listeners
listPayloads
Get available payload options
removeBeacon
Remove a beacon
removeListener
Remove listeners
runBeaconInterpreterC
Execute Beacon Interpreter C through /api/v1/beacons/{bid}/execute/interpreter/pack; typed arguments are passed as the API-native array and packed by Cobalt Strike.
startCobaltStrikeWebsocketStreams
Start default /subscribe/beacons and /subscribe/eventlog stream subscriptions
Tool change history
FAQ
Questions about Cobaltstrike MCP Server
- How do I connect Cobaltstrike MCP Server to Claude?
- The listing records `pip install -r requirements.txt` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop as compatible clients.
- Is Cobaltstrike MCP Server free?
- The listed licence is Apache-2.0. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can Cobaltstrike MCP Server do?
- Cobaltstrike MCP Server documents 21 tools to the agent, including createListener, executeBeaconConsoleAndWait, executeDownload. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.