Installs into .claude/skills of the current project.
Are you the author of Cyber Hunting For Cobalt Strike Beacons?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nexuslinkproductions-cyber-hunting-for-cobalt-strike-beacons)
---
name: cyber-hunting-for-cobalt-strike-beacons
description: "Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP C2 profile pattern matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis."
hide: true
---
<!-- GENERATED:YURI-CODEX-SKILL-ADAPTER:v1 -->
# YURI skill adapter
Authoritative source: `.claude/skills/cyber-hunting-for-cobalt-strike-beacons/SKILL.md`
Authoritative source SHA-256: `0644ac258c9e995c6c99f3ee365464c48d0698d728d14e66d7e9e0a4ca523404`
Source class: `cyber-armed`
Before acting, read the authoritative source file above completely from beginning to end. If the governed source is absent, run `node _SYSTEM/Scripts/skill-recall.mjs --show cyber-hunting-for-cobalt-strike-beacons` and read its complete verified output. Follow that source as the skill body; this adapter is a non-authoritative metadata-and-pointer projection.