Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Go 1.9k 307
Passive service locator, a python sniffer that identifies servers, clients, names and much more
Python 188 37
Beacon Kibana Executable Report. Aggregates Sysmon Network Events With Elasticsearch and Kibana
Shell 241 34
Run zeek with zeekctl in docker
Shell 28 11
This script ships logs from Zeek to AC-Hunter
Shell 4 1
Tools for simulating threats
Shell 70 12
Json file that holds TCP signatures for passive OS fingerprinting
Endpoint detection for remote hosts for consumption by RITA and Elasticsearch
Shell Scripts Used Across ActiveCM Projects
Tools for working with the safelist (formerly whitelist)
Delete Zeek log files until disk usage is under a given threshold
This organization has no public members. You must be a member to see who’s a part of this organization.