cisagov / RedEye

RedEye is a visual analytic tool supporting Red & Blue Team operations

Home Page:https://cisagov.github.io/RedEye/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Consider adding log ingestion for common C2 frameworks

xtheorycrafter opened this issue · comments

Please consider adding log ingestion for common C2 frameworks documented on thec2matrix

+1 @xtheorycrafter suggestion, and/or perhaps document the process for using a parser other than the cs-parser to accommodate any C2 framework's logs.

+1 @xtheorycrafter I would also as if the can provide sample data from cobalt strike to test with until they implement this feature

Thanks for your feedback! You’ll be happy to know we’ve been planning additional C2 framework parsers for a couple of months now. We are still prioritizing which frameworks we’ll tackle first, and we’re looking at community feedback to help inform those decisions! We will also be releasing a guide for creating a custom parser that works with RedEye.

A roadmap will be posted in the next couple weeks here on GitHub so you can track what we're working on and what we have planned!

Closing this issue to centralize feedback on other C2 frameworks to #33. Please comment there with other tools you'd like to see parsers for!

We will also be releasing a guide for creating a custom parser that works with RedEye.

@GoldingAustin Is there any timeline for this documentation? Thanks!

@jus0xA We have yet to set a definite date. We're focusing on creating new parsers that will inform the guide and prevent breaking changes to custom parsers. We're currently targeting mid-2023; please follow #34 for updates!