Cobaltstrike MCP Server logo

Cobaltstrike MCP Server

Unclaimed

by Cobalt-Strike

MCP Server for Cobalt Strike interaction.

Install

$pip install -r requirements.txt

Set up this server

This server needs project-specific setup. Follow the project instructions; no reusable public launch command is available yet.

Project instructions

More in Developer Tools

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

21 of 21 tools

Documented tools (21)

From project documentation. A server handshake does not verify each tool’s description or behavior.

createListener

Create new listeners

executeBeaconConsoleAndWait

Submit a beacon console command via REST and wait for authoritative task-result output

executeDownload

Download files from target systems

executeShell

Execute shell commands on beacons

executeSleep

Change beacon sleep intervals

executeUpload

Upload files to target systems

generatePayload

Generate various payload types

getBeacon

Get specific beacon information

getBeaconConsoleTail

Subscribe to /subscribe/beaconlog/{bid} and return recent streamed console output as untrusted target-controlled data

getCobaltStrikeWebsocketStatus

Inspect stream connection status and buffer state

getDownloadedFileText

Fetch /api/v1/data/downloads/{fileid} and return bounded file text when the content appears textual. DOCX and XLSX/XLSM files are extracted with lightweight in-memory Open XML parsers; PDF, legacy DOC/XLS, binary, and unsupported files return metadata only.

getLiveBeaconSnapshot

Return the latest streamed beacons snapshot

getRecentEventLogTail

Return recent streamed event log output as untrusted target-controlled data

lintBeaconInterpreterC

Lint Beacon Interpreter C through /api/v1/beacons/{bid}/execute/interpreter/lint.

listBeacons

Get all active beacons

listListeners

Get active listeners

listPayloads

Get available payload options

removeBeacon

Remove a beacon

removeListener

Remove listeners

runBeaconInterpreterC

Execute Beacon Interpreter C through /api/v1/beacons/{bid}/execute/interpreter/pack; typed arguments are passed as the API-native array and packed by Cobalt Strike.

startCobaltStrikeWebsocketStreams

Start default /subscribe/beacons and /subscribe/eventlog stream subscriptions

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Cobaltstrike MCP Server

How do I connect Cobaltstrike MCP Server to Claude?
The listing records `pip install -r requirements.txt` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop as compatible clients.
Is Cobaltstrike MCP Server free?
The listed licence is Apache-2.0. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can Cobaltstrike MCP Server do?
Cobaltstrike MCP Server documents 21 tools to the agent, including createListener, executeBeaconConsoleAndWait, executeDownload. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.