
Langage de chasse aux menaces Kestrel : créer des flux de chasse réutilisables, composables et partageables à travers différentes sources de données et renseignements sur les menaces.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Langage de chasse aux menaces Kestrel
|readthedocs| |pypi| |downloads| |codecoverage| |black|
|
*Une chasse aux menaces de bout en bout nécessite généralement une exécution sur plusieurs sources de données/environnements, plus des étapes d'enrichissement/ML/visualisation à n'importe quel endroit du flux de chasse.
.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Exemple Kestrel2
Kestrel est un langage de chasse aux menaces visant à rendre la chasse aux menaces rapide en fournissant une couche d'abstraction pour construire des flux de chasse réutilisables, composables et partageables. Commencez par :
#. Black Hat USA 2024 Kestrel hunting lab_
#. Black Hat USA 2022 Kestrel hunting lab_
#. Black Hat USA 2022 session recording_
Black Hat USA 2024_ pour chasser avec KestrelCNCF Secure AI Summit 2024_Red Hat Research Quarterly_ (RHRQ)Les développeurs de logiciels écrivent du Python ou du Swift plutôt que du code machine pour transformer rapidement la logique métier en applications. Les chasseurs de menaces écrivent Kestrel pour transformer rapidement des hypothèses de menaces en flux de chasse. Nous considérons la chasse aux menaces comme une procédure interactive pour créer des systèmes de détection d'intrusion personnalisés à la volée, et le flux de chasse est à la chasse ce que le flux de contrôle est aux programmes ordinaires.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Aperçu de Kestrel.
Langage Kestrel : un langage de chasse aux menaces permettant à un humain d'exprimer quoi chasser.
Runtime Kestrel : un interpréteur machine qui s'occupe du comment chasser.
Visitez Kestrel documentation_ pour apprendre Kestrel :
Apprenez les concepts et la syntaxe :
A comprehensive introduction to Kestrel_The two key concepts of Kestrel_Interactive tutorial with quiz_Language reference book_Chassez dans votre environnement :
Kestrel runtime installation_How to connect to your data sources_How to execute an analytic hunt step in Python/Docker_How to use Kestrel via API_How to launch Kestrel as a Docker container_Kestrel 2 fait ses débuts au Black Hat USA 2024_. Tout en maintenant la syntaxe du langage de Kestrel 1, nous avons entièrement repensé le runtime de Kestrel 2 pour obtenir de meilleures performances et une syntaxe plus flexible concernant les représentations des entités, attributs et relations.
Fonctionnalités clés de Kestrel 2 :
EXPLAINKestrel 2 est actuellement en bêta, apprenez-en plus sur Kestrel runtime installation_.
Kestrel huntbook_ : cahiers de chasse Kestrel contribués par la communautéKestrel analytics_ : analyses Kestrel contribuées par la communauté#. Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks_
#. Practicing Backward And Forward Tracking Hunts on A Windows Host_
#. Building Your Own Kestrel Analytics and Sharing With the Community_
#. Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow_
#. Try Kestrel in a Cloud Sandbox_
#. Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator_
#. Kestrel Data Retrieval Explained_
Résumé des présentations (visitez Kestrel documentation on talks_ pour en savoir plus) :
Black Hat USA 2024_CNCF Secure AI Summit 2024_Black Hat USA 2023_Infosec Jupyterthon 2022_ [IJ'22 live hunt recording_]Black Hat USA 2022_ [BH'22 recording_ | BH'22 hunting lab_]Cybersecurity Automation Workshop_SC eSummit on Threat Hunting & Offense Security_ (inscription/lecture gratuite)Infosec Jupyterthon 2021_ [IJ'21 live hunt recording_]BlackHat Europe 2021_SANS Threat Hunting Summit 2021_ : [SANS'21 session recording_]RSA Conference 2021_ : [RSA'21 session recording_]Rejoignez le canal Slack Kestrel :
Obtenez une slack invitation_ pour rejoindre l'Open Cybersecurity Alliance workspace_
.. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: Logo OCA
Rejoignez le canal kestrel pour poser des questions et entrer en contact avec d'autres chasseurs
Contribuez au développement du langage (Apache License 2.0_) :
GitHub Issue_ pour signaler des bogues et suggérer de nouvelles fonctionnalitéscontributing guideline_ pour soumettre votre pull requestgovernance documentation_ concernant la fusion de PR, la publication et la divulgation de vulnérabilitésPartagez votre cahier de chasse et vos analyses :
Kestrel huntbook_Kestrel analytics_.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/
.. _A comprehensive introduction to Kestrel: https://kestrel.readthedocs.io/en/latest/overview/ .. _The two key concepts of Kestrel: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _Interactive tutorial with quiz: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel runtime installation: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _How to connect to your data sources: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _How to execute an analytic hunt step in Python/Docker: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _Language reference book: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _How to use Kestrel via API: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _How to launch Kestrel as a Docker container: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel documentation on talks: https://kestrel.readthedocs.io/en/latest/talks.html
.. _Kestrel huntbook: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel analytics: https://github.com/opencybersecurityalliance/kestrel-analytics
.. _Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Practicing Backward And Forward Tracking Hunts on A Windows Host: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _Building Your Own Kestrel Analytics and Sharing With the Community: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _Try Kestrel in a Cloud Sandbox: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel Data Retrieval Explained: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/
.. _RSA Conference 2021: https://www.rsaconference.com/Library/presentation/USA/2021/The%20Game%20of%20Cyber%20Threat%20Hunting%20The%20Return%20of%20the%20Fun .. _RSA'21 session recording: https://www.youtube.com/watch?v=-Xb086R0JTk .. _SANS Threat Hunting Summit 2021: https://www.sans.org/blog/a-visual-summary-of-sans-threat-hunting-summit-2021/ .. _SANS'21 session recording: https://www.youtube.com/watch?v=gyY5DAWLwT0 .. _BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#an-open-stack-for-threat-hunting-in-hybrid-cloud-with-connected-observability-25112 .. _Infosec Jupyterthon 2021: https://infosecjupyterthon.com/2021/agenda.html .. _IJ'21 live hunt recording: https://www.youtube.com/embed/nMnHBnYfIaI?start=20557&end=22695 .. _Infosec Jupyterthon 2022: https://infosecjupyterthon.com/2022/agenda.html .. _IJ'22 live hunt recording: https://www.youtube.com/embed/8Mw1yyYkeqM?start=23586&end=26545 .. _SC eSummit on Threat Hunting & Offense Security: https://www.scmagazine.com/esummit/automating-the-hunt-for-advanced-threats .. _Cybersecurity Automation Workshop: http://www.cybersecurityautomationworkshop.org/ .. _Black Hat USA 2024: https://www.blackhat.com/us-24/arsenal/schedule/index.html#kestrel--hunt-for-threats-across-security-data-lakes-39321 .. _Black Hat USA 2023: https://www.blackhat.com/us-23/arsenal/schedule/index.html#identity-threat-hunting-with-kestrel-33662 .. _Black Hat USA 2022: https://www.blackhat.com/us-22/arsenal/schedule/index.html#streamlining-and-automating-threat-hunting-with-kestrel-28014 .. _BH'22 recording: https://www.youtube.com/watch?v=tf1VLIpFefs .. _Black Hat USA 2022 session recording: https://www.youtube.com/watch?v=tf1VLIpFefs .. _BH'22 hunting lab: https://mybinder.org/v2/gh/opencybersecurityalliance/black-hat-us-2022/HEAD?filepath=demo .. _Black Hat USA 2022 Kestrel hunting lab: https://mybinder.org/v2/gh/opencybersecurityalliance/black-hat-us-2022/HEAD?filepath=demo .. _Black Hat USA 2024 Kestrel hunting lab: https://github.com/opencybersecurityalliance/black-hat-us-2024 .. _Red Hat Research Quarterly: https://research.redhat.com/blog/article/team-threat-hunting-on-a-container-platform-kestrel-as-a-service/ .. _CNCF Secure AI Summit 2024: https://secureaisummit2024.sched.com/event/1dBWF/elevate-cloud-threat-hunting-with-ai-kenneth-peeples-maya-costantini-red-hat
.. _slack invitation: https://join.slack.com/t/open-cybersecurity/shared_invite/zt-19pliofsm-L7eSSB8yzABM2Pls1nS12w .. _Open Cybersecurity Alliance workspace: https://open-cybersecurity.slack.com/ .. _GitHub Issue: https://github.com/opencybersecurityalliance/kestrel-lang/issues .. _contributing guideline: CONTRIBUTING.rst .. _governance documentation: GOVERNANCE.rst .. _Apache License 2.0: LICENSE.md
.. |readthedocs| image:: https://readthedocs.org/projects/kestrel/badge/?version=latest :target: https://kestrel.readthedocs.io/en/latest/?badge=latest :alt: Statut de la documentation
.. |pypi| image:: https://img.shields.io/pypi/v/kestrel-jupyter :target: https://pypi.python.org/pypi/kestrel-jupyter :alt: Dernière version
.. |downloads| image:: https://img.shields.io/pypi/dm/kestrel-core :target: https://pypistats.org/packages/kestrel-core :alt: Téléchargements PyPI
.. |codecoverage| image:: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang/branch/develop/graph/badge.svg?token=HM4ax10IW3 :target: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang :alt: Couverture de code
.. |black| image:: https://img.shields.io/badge/code%20style-black-000000.svg :target: https://github.com/psf/black :alt: Style de code : Black