Cobalt Strike MCP Server
An MCP (Model Context Protocol) server that provides access to Cobalt Strike API operations.
Features
- Automatic Authentication: Authenticates with Cobalt Strike API and manages bearer token
- Dynamic Tool Generation: Automatically creates MCP tools from the OpenAPI specification
- Full API Coverage: Exposes all Cobalt Strike API operations as MCP tools
Setup
- Install dependencies:
pip install -r requirements.txt
- Configure environment variables (copy
.env.exampleto.envand edit):
cp .env.example .env
- Set your Cobalt Strike credentials:
export CS_BASE_URL="https://your-cs-server:50443"
export CS_USERNAME="your-username"
export CS_PASSWORD="your-password"
export CS_VERIFY_SSL="false" # Set to "true" if using valid SSL cert
Usage
Running the Server
python server.py
Using with MCP Client
Add to your MCP client configuration (e.g., Claude Desktop):
{
"mcpServers": {
"cobalt-strike": {
"command": "python",
"args": ["/path/to/CS-MCP/server.py"],
"env": {
"CS_BASE_URL": "https://your-cs-server:50443",
"CS_USERNAME": "your-username",
"CS_PASSWORD": "your-password",
"CS_VERIFY_SSL": "false"
}
}
}
}
How It Works
- Authentication: On startup, the server authenticates with
/api/auth/loginand retrieves a bearer token - API Client Initialization: Creates an HTTP client with the bearer token in the Authorization header
- OpenAPI Spec Loading: Fetches the OpenAPI specification from
/v3/api-docs - Tool Generation: Dynamically creates MCP tools for each API operation
- Request Handling: Routes tool calls to the appropriate API endpoints with proper authentication
Environment Variables
CS_BASE_URL: Base URL of the Cobalt Strike serverCS_USERNAME: Username for authentication (required)CS_PASSWORD: Password for authentication (required)CS_VERIFY_SSL: Whether to verify SSL certificates (default:false)
Security Notes
- Store credentials securely (use environment variables, not hardcoded values)
- Consider using SSL certificate verification in production (
CS_VERIFY_SSL=true) - The bearer token is managed automatically and refreshed as needed
Metadata
Release files for iflow-mcp_ibaic_cobalt-strike-mcp 1.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iflow_mcp_ibaic_cobalt_strike_mcp-1.0.2.tar.gz | 27.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iflow_mcp_ibaic_cobalt_strike_mcp-1.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 59.7 kB
Release files / iflow_mcp_ibaic_cobalt_strike_mcp-1.0.2.tar.gz
| Download URL | iflow_mcp_ibaic_cobalt_strike_mcp-1.0.2.tar.gz |
|---|---|
| Size | 27.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b6646f254c9b8926e49f2568be290701c444acb117969bb40fae4761ef2122ea
|
|
BLAKE2b-256 checksum How to use checksums |
1cc42374260c4500183e414033a8e770a8be5279c08b527f6e46aa1cfa29e179
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.9.26 {"installer":{"name":"uv","version":"0.9.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / iflow_mcp_ibaic_cobalt_strike_mcp-1.0.2-py3-none-any.whl
| Download URL | iflow_mcp_ibaic_cobalt_strike_mcp-1.0.2-py3-none-any.whl |
|---|---|
| Size | 32.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f8d09b70a195993d37803830cdef9ed2dc1776b1e28d8e0b7cfbb9db23474a4b
|
|
BLAKE2b-256 checksum How to use checksums |
49ddf97e4517f0278bbcbb6c4afb86710aa4f0343bd9d4aa4570942a06dd5cf3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.9.26 {"installer":{"name":"uv","version":"0.9.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|