Itinerary to Defeat Yet Another Beacon Implementation @FIRSTdotorg
Itinerary to Defeat Yet Another Beacon Implementation  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 2 hours ago
Naoki Takayama (Internet Initiative Japan Inc., JP)

Cobalt Strike remains one of the most widely abused post‑exploitation frameworks, favored by both cybercrime groups and state‑sponsored APT actors. In recent years, defenders have significantly improved their tooling and techniques for detecting and analyzing the Cobalt Strike Beacon. As a response to this, some threat actors have shifted toward reimplementation of the Cobalt Strike Beacon written in modern programming languages such as Rust and Go. These new variants offer improved stealth, flexible customization, and inherent evasive characteristics originating from their language ecosystems.

This talk will present an in‑depth analysis of these emerging variants, exploring their architecture, behaviors, and notable samples observed in the wild. Additionally, we will offer practical strategies for blue teams, including configuration‑extraction methods and YARA detection rules designed to identify these new threats.

---

Naoki Takayama is a security researcher at Internet Initiative Japan, Inc. As a member of IIJ-SECT, the private CSIRT of his company, he is engaged in threat research and incident response. His research focuses on malware and tactics used in targeted attacks. He has spoken at BSides Tokyo and VB in the past.
Itinerary to Defeat Yet Another Beacon ImplementationCVE Record Format - Purl and CPE WorkshopBeyond CVEs: Mastering the Landscape with Vulnerability-LookupFrom JSON to Clarity: Practical Tools for SBOM InterpretationVersus KillnetDeriving CVSS from Multi-Scenario Attack Graphs: A Reproducible, Auditable Scoring MethodUnmasking Cyber Security: Rethinking Small to Medium Business Security AwarenessFrom Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated ...From CVD to Secure Releases: Automating Security from Source to ReleasesOnly Seeing Stars: Enabling the Open Source Scripting Community with OCSFInside the Information Stealer Ecosystem: From Compromise to CountermeasureImproving Security Across Nations with FIRST: Tom Millar, FIRST TLP SIG Co-chair
FIRST |

Itinerary to Defeat Yet Another Beacon Implementation

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER