ACTIVE DASHBOARD

16 bookmarks
Custom sorting
RITA - Active Countermeasures
RITA - Active Countermeasures
Real Intelligence Threat Analytics (R-I-T-A) is an open-source framework for detecting command and control communication through network traffic analysis.
The RITA framework ingests Zeek logs in TSV or JSON format, or PCAPs converted to Zeek logs for analysis.
hunt teaming. This is where an organization has a team of individuals who actively go looking for evil on a network. This makes some significant assumptions
VSagent. It hides its Command and Control (C2) traffic into the “__VIEWSTATE” parameter, which is base64 encoded. Further, it beacons every 30 seconds.
Beacon Detection: Search for signs of beaconing behavior in and out of your network
DNS Tunneling Detection: Identify signs of DNS-based covert channels
RITA now uses a new database called ClickHouse. It uses a storage approach that is significantly different from the previous MongoDB setup and is much better suited for handling the static records generated by a Zeek sensor
cd wget https://github.com/activecm/rita/releases/download/v5.0.0-beta/rita-v5.0.0-beta.tar.gz tar -xzvf rita-v5.0.0-beta.tar.gz cd rita-v5.0.0-beta-installer ./install_rita.sh localhost
·activecountermeasures.com·
RITA - Active Countermeasures
Sign Up
Sign Up
Build and deploy software collaboratively with the power of AI without spending a second on setup.
·replit.com·
Sign Up
Cursor
Cursor
Cursor is the best way to build software with AI.
·cursor.com·
Cursor