Skip to content

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

License

Notifications You must be signed in to change notification settings

outflanknl/RedELK

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Jan 31, 2025
3c54953 · Jan 31, 2025
Nov 28, 2022
Oct 16, 2022
Jan 31, 2025
Mar 4, 2023
Jan 31, 2025
Oct 31, 2023
Oct 16, 2022
Nov 5, 2021
Mar 19, 2023
Mar 4, 2023
Oct 16, 2022
Oct 16, 2022
Oct 16, 2022
Feb 20, 2022
Sep 27, 2023
Oct 16, 2022

Repository files navigation

Build docker base image (dev) Build docker elasticsearch image (dev) Build docker jupyter image (dev) Build docker kibana image (dev) Build docker logstash image (dev)

Red Team's SIEM - tool for Red Teams for tracking and alarming about Blue Team activities as well as enhanced usability in long term operations.

  1. Enhanced usability and overview for the red team operators by creating a central location where all relevant operational logs from multiple teamservers are collected and enriched. This is great for historic searching within the operation as well as giving a read-only view on the operation (e.g. for the White Team). Especially useful for multi-scenario, multi-teamserver, multi-member and multi-month operations. Also, super easy ways for viewing all screenshots, IOCs, keystrokes output, etc. \o/
  2. Spot the Blue Team by having a central location where all traffic logs from redirectors are collected and enriched. Using specific queries its now possible to detect that the Blue Team is investigating your infrastructure.

Background info

Check the wiki for info on usage or one the blog posts or presentations listed below:

Installation

Check the wiki for manual installation manual. There are also Ansible playbooks maintained by others:

Conceptual overview

Here's a conceptual overview of how RedELK works.

Authors and contribution

This project is developed and maintained by:

We welcome contributions! Contributions can be both in code, as well as in ideas you might have for further development, alarms, usability improvements, etc.