  1. Cisco has a good article on Cobalt Strike. tl;dr, it's more likely to be run against your network than from an endpoint inside. IPS on firewall and script detection on A/V probably your best bets for identifying and stopping.
  2. Would you mind sharing how you were able to get the new tabs to show up? I'm having some difficulty after importing the scripts. Thank you! Edit: Turns out I'm a dummy. I didn't put it together that Custom Tabs itself was something that needed to be installed.
