RedELK

红队的 SIEM - 红队的工具,用于跟踪和报警蓝队的活动,在长期运行中具有更好的可用性。「Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.」

Github星跟蹤圖

Build docker base image (dev)
Build docker elasticsearch image (dev)
Build docker jupyter image (dev)
Build docker kibana image (dev)
Build docker logstash image (dev)

Red Team's SIEM - tool for Red Teams for tracking and alarming about Blue Team activities as well as enhanced usability in long term operations.

  1. Enhanced usability and overview for the red team operators by creating a central location where all relevant operational logs from multiple teamservers are collected and enriched. This is great for historic searching within the operation as well as giving a read-only view on the operation (e.g. for the White Team). Especially useful for multi-scenario, multi-teamserver, multi-member and multi-month operations. Also, super easy ways for viewing all screenshots, IOCs, keystrokes output, etc. \o/
  2. Spot the Blue Team by having a central location where all traffic logs from redirectors are collected and enriched. Using specific queries its now possible to detect that the Blue Team is investigating your infrastructure.

Background info

Check the wiki for info on usage or one the blog posts or presentations listed below:

Installation

Check the wiki for manual installation manual. There are also Ansible playbooks maintained by others:

Conceptual overview

Here's a conceptual overview of how RedELK works.

Authors and contribution

This project is developed and maintained by:

We welcome contributions! Contributions can be both in code, as well as in ideas you might have for further development, alarms, usability improvements, etc.

主要指標

概覽
名稱與所有者outflanknl/RedELK
主編程語言Python
編程語言Shell (語言數: 5)
平台
許可證BSD 3-Clause "New" or "Revised" License
所有者活动
創建於2018-10-03 15:55:05
推送於2025-01-31 09:24:00
最后一次提交2025-01-31 10:24:00
發布數15
最新版本名稱v2.0.0-beta.6 (發布於 2022-02-20 23:08:43)
第一版名稱v0.8.0-beta (發布於 )
用户参与
星數2.4k
關注者數78
派生數375
提交數1.1k
已啟用問題?
問題數142
打開的問題數26
拉請求數155
打開的拉請求數1
關閉的拉請求數14
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?