opencybersecurityalliance / kestrel-analytics

This repository hosts community contributed Kestrel analytics

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Community-Contributed Kestrel Analytics

This repository hosts community-contributed Kestrel analytics.

For Kestrel hunt-flows/huntbooks, visit the sister repo kestrel-huntbook.

What is Kestrel?

What is Kestrel analytics?

  • Kestrel analytics is one type of hunt steps, of which a hunt-flow is composed. This type of hunt step provides foreign language interfaces to non-Kestrel hunting modules to apply any external logic like ML detection, TI enrichment, and visualization.
  • Try a Kestrel analytics in a cloud sandbox:

How to Contribute

  1. Submit a PR with a description of the new analytics to add.
  2. If the analytics has testing data, consider to put the data in data-bucket-kestrel
  3. Get approval from one of the maintainers.
  4. Share the link of your Kestrel analytics with others.

About

This repository hosts community contributed Kestrel analytics

License:Apache License 2.0


Languages

Language:Python 85.7%Language:Perl 7.7%Language:Dockerfile 5.4%Language:Shell 1.1%