Obtaining an API Token
To get started logging you need an API token. To use the utilities mentioned below you will want to generate an API token with an expiration date. For custom logging tools, you can consider using thelogin action with the API.
Read more about this process here:
Authentication
Setting up Syncing with Cobalt Strike
GitHub - GhostManager/cobalt_sync
Note: Cobalt Strike does not associate console output with the original command. Therefore, cobalt_sync cannot automatically complete the output fields for log entries. Job IDs may be available for CObalt Strike in the future.
Setting up Syncing with Mythic
GitHub - GhostManager/mythic_sync
Note: Since Mythic associates output with the original command, the mythic_sync project will retroactively update previous log entries when output is received. This will overwrite any additional context added to the original entry within Ghostwriter before the new output was received.