# getBeaconConsoleTail

Get recent streamed console output for a beacon.

Agent View of the PolicyLayer registry record for `getBeaconConsoleTail`. HTML page: https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getbeaconconsoletail

## Facts

- Tool: `getBeaconConsoleTail`
- Server: Cobalt Strike MCP Server (`cobalt-strike/cobaltstrike-mcp-server`) — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server.md
- Homepage: https://github.com/Cobalt-Strike/cobaltstrike-mcp-server
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "getBeaconConsoleTail",
    "arguments": {}
  }
}
```

## Why getBeaconConsoleTail is rated Low

This tool retrieves console output from a beacon (C2 agent) without modifying or executing anything. It is a Read operation by function. However, severity is high because Cobalt Strike is inherently an offensive tool used to simulate attackers, and access to beacon console output could reveal sensitive operational details, command history, or exfiltrated data.

From the tool's own definition: "Tool name contains 'get' and description states 'Get recent streamed console output' — retrieves data without modification. However, the context is Cobalt Strike, a command & control framework used for adversary simulation and offensive operations."

## Use case

AI agents call getBeaconConsoleTail to retrieve information from Cobalt Strike MCP Server without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Cobalt Strike MCP Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "getBeaconConsoleTail": {}
  }
}
```

## Other tools on Cobalt Strike MCP Server (8)

- `executeBeaconConsoleAndWait` — Execute — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/executebeaconconsoleandwait.md
- `lintBeaconInterpreterC` — Execute — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/lintbeaconinterpreterc.md
- `runBeaconInterpreterC` — Execute — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/runbeaconinterpreterc.md
- `startCobaltStrikeWebsocketStreams` — Execute — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/startcobaltstrikewebsocketstreams.md
- `getCobaltStrikeWebsocketStatus` — Read — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getcobaltstrikewebsocketstatus.md
- `getDownloadedFileText` — Read — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getdownloadedfiletext.md
- `getLiveBeaconSnapshot` — Read — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getlivebeaconsnapshot.md
- `getRecentEventLogTail` — Read — https://policylayer.com/tools/cobalt-strike-cobaltstrike-mcp-server/getrecenteventlogtail.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=cobalt-strike-cobaltstrike-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/cobalt-strike-cobaltstrike-mcp-server
