{"id":13844265,"url":"https://github.com/Cobalt-Strike/teamserver-prop","last_synced_at":"2025-07-11T22:31:14.983Z","repository":{"id":59436373,"uuid":"394630000","full_name":"Cobalt-Strike/teamserver-prop","owner":"Cobalt-Strike","description":"TeamServer.prop is an optional properties file used by the Cobalt Strike teamserver to customize the settings used to validate screenshot and keylog callback data, which allows you to tweak the fix for the “HotCobalt” vulnerability. This repository contains an example file that contains the default settings.","archived":false,"fork":false,"pushed_at":"2023-09-19T13:19:51.000Z","size":9,"stargazers_count":59,"open_issues_count":0,"forks_count":18,"subscribers_count":2,"default_branch":"main","last_synced_at":"2024-02-12T21:19:54.861Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Cobalt-Strike.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-08-10T11:38:27.000Z","updated_at":"2024-07-16T19:04:48.977Z","dependencies_parsed_at":"2024-07-16T19:04:43.529Z","dependency_job_id":"1d7fd1af-bcb0-4109-ae13-8047b8d38e38","html_url":"https://github.com/Cobalt-Strike/teamserver-prop","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Cobalt-Strike/teamserver-prop","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cobalt-Strike%2Fteamserver-prop","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cobalt-Strike%2Fteamserver-prop/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cobalt-Strike%2Fteamserver-prop/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cobalt-Strike%2Fteamserver-prop/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Cobalt-Strike","download_url":"https://codeload.github.com/Cobalt-Strike/teamserver-prop/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Cobalt-Strike%2Fteamserver-prop/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264909966,"owners_count":23682096,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:02:38.846Z","updated_at":"2025-07-11T22:31:14.600Z","avatar_url":"https://github.com/Cobalt-Strike.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# README\n\nThe Cobalt Strike 4.4 release introduced an optional file, **TeamServer.prop**, that contains a number of  parameters that can be used to customize the settings used to validate screenshot and keylog callback data. \n\nThe Cobalt Strike 4.7.1 release introduced new settings for the maximum number of beacons, thresholds for new beacons and beacon XSS validation. \n\nThe file is not included by default and a warning appears if it cannot be found when the teamserver starts up, but the absence of the file does not break the teamserver. \n\nThis repository contains an example TeamServer.prop. We don't recommend that the defaults values are changed but if this is something that you want to do, simply copy the file into your Cobalt Strike directory and (re)start the teamserver.\n\n- Lines starting with \"#\" are comments.\n\n- **limits.\\*_data_maxlen** is the maximum size of screenshot/keylog data that will be processed. Callbacks exceeding this limit will be rejected.\n- **limits.\\*_validated=false** means that the three following \"**..._maxlen**\" settings are ignored\n- Setting any of the \"**..._maxlen**\" settings to zero will disable that particular setting\n- **limits.\\*_diskused_percent** sets the threshold for callback processing. Callbacks are rejected when disk usage exceeds the specified percentage\n    - **limits.\\*_diskused_percent=0** (zero) disables this setting\n    - Valid values are 0-99\n\n\nAdd a limit to the number of beacons allowed (spam protection).\n- **limits.beacons_max** is the maximum number of beacon allowed (default is *500*)\n    - **limits.beacons_max=0** (zero) disables this setting\n\nThreshold rate for adding new beacons (spam protection).\nAdd a limit to the number of new beacons added within a specified time period.\nWhen the limit is exceeded, disable accepting new beacons for the disable duration.\n- **limits.beacon_rate_period** milliseconds of the time period (default is *30000*)\n    - **limits.beacon_rate_period=0** (zero) disables this setting\n- **limits.beacon_rate_maxperperiod** new beacons allowed during time period (default is *50*)\n    - **limits.beacon_rate_maxperperiod=0** (zero) disables this setting\n- **limits.beacon_rate_disableduration** milliseconds to disable when threshold is exceeded (default is *600000*)\n    - **limits.beacon_rate_disableduration=0** (zero) disables this setting\n\nPerform XSS Validation on select new beacon metadata (spam protection).\n- **limits.beacons_xssvalidated** (default is *true*)\n    - **limits.beacons_xssvalidated=false** disables this setting\n\nOverride the timestamp formatting pattern used for logfiles.\n- **logfile.timestamp.pattern** (default is *MM/dd HH:mm:ss zzz*)\n    - **logfile.timestamp.pattern=yyyy-MM-dd HH:mm:ss zzz**\n\nOverride the timezone used for the log files\n- **logfile.timezone** (default is *UTC*)\n    - **logfile.timezone=America/Los_Angeles**\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FCobalt-Strike%2Fteamserver-prop","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FCobalt-Strike%2Fteamserver-prop","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FCobalt-Strike%2Fteamserver-prop/lists"}