rita-legacy

Traffic analyzer

Analyzes network traffic to detect command and control communication behaviors.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

GitHub

3k stars
112 watching
362 forks
Language: Go
last commit: about 2 years ago
analysisanalyticsbeaconbeacon-snifferbhisblueteambro-idsdgadnsdns-tunnelinglogsnetwork-trafficoffensive-countermeasuresritascanningsecuritythreat

Related projects:

RepositoryDescriptionStars
activecm/ritaA framework for detecting malicious communication patterns in network traffic by analyzing Zeek logs.215
stamparm/maltrailDetects and analyzes malicious traffic patterns to identify potential security threats.6,642
raihan2006i/active_admin_paranoiaAdds batch restore and archive actions to ActiveAdmin resource index pages29
cybermonitor/apt_cybercriminal_campagin_collectionsA collection of APT and cybercriminal campaign data, including malware samples and threat intelligence3,757
zabbix/zabbixAn enterprise-class monitoring solution designed to track performance and availability of IT resources and services in real-time.4,484
opennhp/opennhpA Zero Trust protocol that leverages resource-hiding and encryption to safeguard servers and data from attackers13,520
eremit4/cs-discoveryDetects malicious servers in network traffic by analyzing encoded byte patterns20
security-onion-solutions/securityonionAn integrated security monitoring and threat hunting platform that collects, analyzes, and responds to network traffic data3,347
nationalsecurityagency/ghidraA software reverse engineering framework with disassembler and analysis tools52,492
activecm/beakerAggregates Microsoft Sysmon network events with Elasticsearch and Kibana for threat hunting analysis287
ch3k1/squidmagicAnalyzes web-based network traffic to detect malicious command and control servers using Squid proxy server and Spamhaus78
akamai/ludaDevelops real-time URL-based malware detection system using regexes and clustering74
byt3bl33d3r/deathstarAutomates gaining Domain and/or Enterprise Admin rights in Active Directory environments using offensive TTPs1,592
google/tsunami-security-scannerAn open-source network security scanner with an extensible plugin system to detect high-severity vulnerabilities.8,291
orange-cyberdefense/goadA pentest active directory LAB project providing a vulnerable environment for practice.5,620