# Cobalt Strike MCP Server MCP server

Agent View of the PolicyLayer registry record for Cobalt Strike MCP Server: identity, probed posture, risk grade, and all 9 tools classified. HTML page: https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server

## Facts

- Server id: `cobalt-strike/cobaltstrike-mcp-server`
- Homepage: https://github.com/Cobalt-Strike/cobaltstrike-mcp-server
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 9
- Tool categories present: Execute, Read
- Tags: cobalt strike cobaltstrike mcp server, automation
- Record last modified: 2026-06-11T16:19:19.896Z

## Tools (9)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `executeBeaconConsoleAndWait` | Execute | High | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/executebeaconconsoleandwait.md |
| `lintBeaconInterpreterC` | Execute | High | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/lintbeaconinterpreterc.md |
| `runBeaconInterpreterC` | Execute | High | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/runbeaconinterpreterc.md |
| `startCobaltStrikeWebsocketStreams` | Execute | High | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/startcobaltstrikewebsocketstreams.md |
| `getBeaconConsoleTail` | Read | Low | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getbeaconconsoletail.md |
| `getCobaltStrikeWebsocketStatus` | Read | Low | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getcobaltstrikewebsocketstatus.md |
| `getDownloadedFileText` | Read | Low | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getdownloadedfiletext.md |
| `getLiveBeaconSnapshot` | Read | Low | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getlivebeaconsnapshot.md |
| `getRecentEventLogTail` | Read | Low | https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getrecenteventlogtail.md |

## Tool descriptions

- `executeBeaconConsoleAndWait` — Execute a beacon console command and wait for streamed console output.
- `runBeaconInterpreterC` — Execute Beacon Interpreter C source using /execute/interpreter/pack.
- `startCobaltStrikeWebsocketStreams` — Start the default Cobalt Strike WebSocket subscriptions.
- `getBeaconConsoleTail` — Get recent streamed console output for a beacon.
- `getCobaltStrikeWebsocketStatus` — Get current status for Cobalt Strike WebSocket stream subscriptions.
- `getDownloadedFileText` — Return downloaded file contents when the file is text, otherwise metadata only.
- `getLiveBeaconSnapshot` — Get the latest streamed beacon snapshot.
- `getRecentEventLogTail` — Get recent streamed Cobalt Strike event log output.

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Yaver (805 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md
- Crow (577 tools) — https://policylayer.com/tools/kh0pper-crow.md
- TinyFn (572 tools) — https://policylayer.com/tools/io-tinyfn-tinyfn.md
- Mcp (571 tools) — https://policylayer.com/tools/io-github-2s-io-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=cobalt-strike-cobaltstrike-mcp-server · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/cobalt-strike-cobaltstrike-mcp-server
