
Kestrel threat hunting language: विभिन्न डेटा स्रोतों और threat intel के पार पुन: प्रयोज्य, संयोजनीय और साझा करने योग्य huntflows का निर्माण।
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Kestrel Threat Hunting Language
|readthedocs| |pypi| |downloads| |codecoverage| |black|
|
*एक एंड-टू-एंड साइबर थ्रेट हंट को आमतौर पर कई डेटास्रोतों/वातावरणों में निष्पादन के साथ-साथ हंटफ्लो में कहीं भी संवर्धन/एमएल/विज़ुअलाइज़ेशन चरणों की आवश्यकता होती है।
.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Kestrel2 Example
Kestrel एक थ्रेट हंटिंग भाषा है जिसका उद्देश्य साइबर थ्रेट हंटिंग को तेज़ बनाना है, जो पुन: प्रयोज्य, संयोजनीय और साझा करने योग्य हंट-फ्लो बनाने के लिए अमूर्तता की एक परत प्रदान करता है। इससे शुरू करें:
#. Black Hat USA 2024 Kestrel हंटिंग लैब_
#. Black Hat USA 2022 Kestrel हंटिंग लैब_
#. Black Hat USA 2022 सत्र रिकॉर्डिंग_
Black Hat USA 2024_ में पंजीकरण करेंCNCF Secure AI Summit 2024_ में Kestrel और AI वार्ताRed Hat Research Quarterly_ (RHRQ) में स्केलेबल Kestrel परिनियोजन सीखेंसॉफ्टवेयर डेवलपर्स व्यावसायिक तर्क को तुरंत एप्लिकेशन में बदलने के लिए मशीन कोड की तुलना में Python या Swift लिखते हैं। थ्रेट हंटर्स थ्रेट परिकल्पनाओं को तुरंत हंट-फ्लो में बदलने के लिए Kestrel लिखते हैं। हम थ्रेट हंटिंग को तुरंत कस्टमाइज़्ड घुसपैठ का पता लगाने वाली प्रणाली बनाने के लिए एक इंटरैक्टिव प्रक्रिया के रूप में देखते हैं, और हंट-फ्लो हंट्स के लिए वैसा ही है जैसा कंट्रोल-फ्लो सामान्य प्रोग्रामों के लिए है।
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Kestrel overview.
Kestrel भाषा: एक थ्रेट हंटिंग भाषा जो मनुष्य के लिए क्या शिकार करना है यह व्यक्त करने के लिए बनाई गई है।
Kestrel रनटाइम: एक मशीन दुभाषिया जो कैसे शिकार करना है से संबंधित है।
Kestrel सीखने के लिए Kestrel दस्तावेज़ीकरण_ पर जाएँ:
अवधारणाएँ और सिंटैक्स सीखें:
Kestrel का व्यापक परिचय_Kestrel की दो प्रमुख अवधारणाएँ_क्विज़ के साथ इंटरैक्टिव ट्यूटोरियल_भाषा संदर्भ पुस्तिका_अपने वातावरण में शिकार करें:
Kestrel रनटाइम स्थापना_अपने डेटा स्रोतों से कैसे जुड़ें_Python/Docker में एक विश्लेषणात्मक हंट चरण कैसे निष्पादित करें_API के माध्यम से Kestrel का उपयोग कैसे करें_Docker कंटेनर के रूप में Kestrel कैसे लॉन्च करें_Kestrel 2 Black Hat USA 2024_ में शुरू हुआ। Kestrel 1 से भाषा सिंटैक्स को बनाए रखते हुए, हमने एंटिटी, गुण और संबंध प्रतिनिधित्व के संबंध में बेहतर प्रदर्शन और अधिक लचीला सिंटैक्स प्राप्त करने के लिए Kestrel 2 रनटाइम को पूरी तरह से फिर से डिज़ाइन किया है।
Kestrel 2 की प्रमुख विशेषताएं:
व्याख्या के बजाय जस्ट-इन-टाइम संकलन
आलसी मूल्यांकन और नया EXPLAIN कमांड
गहराई से नेस्टेड क्वेरी के साथ डेटा लेकहाउस अनुकूलन
STIX के अलावा OCSF और OpenTelemetry एंटिटी/गुण समर्थन
Kestrel 2 वर्तमान में बीटा में है, Kestrel रनटाइम स्थापना_ पर और जानें।
Kestrel हंटबुक_: समुदाय द्वारा योगदान की गई Kestrel हंटबुकKestrel विश्लेषिकी_: समुदाय द्वारा योगदान की गई Kestrel विश्लेषिकी#. निर्धारित विंडोज कार्यों से लगातार खतरों की खोज के लिए हंटबुक बनाना_
#. विंडोज होस्ट पर बैकवर्ड और फॉरवर्ड ट्रैकिंग हंट्स का अभ्यास करना_
#. अपनी खुद की Kestrel विश्लेषिकी बनाएं और समुदाय के साथ साझा करें_
#. Kestrel और SysFlow के साथ संकर क्लाउड में ओपन हंटिंग स्टैक स्थापित करना_
#. क्लाउड सैंडबॉक्स में Kestrel आज़माएं_
#. securitydatasets.com और Kestrel PowerShell डिऑबफस्केटर के साथ मज़ा_
#. Kestrel डेटा पुनर्प्राप्ति समझाया गया_
वार्ता सारांश (विवरण जानने के लिए Kestrel वार्ताओं पर दस्तावेज़ीकरण_ पर जाएँ):
Black Hat USA 2024_CNCF Secure AI Summit 2024_Black Hat USA 2023_Infosec Jupyterthon 2022_ [IJ'22 लाइव हंट रिकॉर्डिंग_]Black Hat USA 2022_ [BH'22 रिकॉर्डिंग_ | BH'22 हंटिंग लैब_]Cybersecurity Automation Workshop_SC eSummit on Threat Hunting & Offense Security_ (पंजीकरण/प्लेबैक मुफ़्त)Infosec Jupyterthon 2021_ [IJ'21 लाइव हंट रिकॉर्डिंग_]BlackHat Europe 2021_Kestrel स्लैक चैनल से जुड़ें:
Open Cybersecurity Alliance कार्यक्षेत्र_ में शामिल होने के लिए स्लैक आमंत्रण_ प्राप्त करें
.. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: OCA logo
प्रश्न पूछने और अन्य हंटर्स से जुड़ने के लिए kestrel चैनल से जुड़ें
भाषा विकास में योगदान दें (Apache License 2.0_):
GitHub Issue_ बनाएंयोगदान दिशानिर्देश_ का पालन करेंशासन दस्तावेज़ीकरण_ देखेंअपनी हंटबुक और विश्लेषिकी साझा करें:
Kestrel हंटबुक_Kestrel विश्लेषिकी_.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/ .. _Kestrel का व्यापक परिचय: https://kestrel.readthedocs.io/en/latest/overview/ .. _Kestrel की दो प्रमुख अवधारणाएँ: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _क्विज़ के साथ इंटरैक्टिव ट्यूटोरियल: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel रनटाइम स्थापना: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _अपने डेटा स्रोतों से कैसे जुड़ें: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _Python/Docker में एक विश्लेषणात्मक हंट चरण कैसे निष्पादित करें: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _भाषा संदर्भ पुस्तिका: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _API के माध्यम से Kestrel का उपयोग कैसे करें: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _Docker कंटेनर के रूप में Kestrel कैसे लॉन्च करें: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel वार्ताओं पर दस्तावेज़ीकरण: https://kestrel.readthedocs.io/en/latest/talks.html
.. _Kestrel हंटबुक: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel विश्लेषिकी: https://github.com/opencybersecurityalliance/kestrel-analytics
.. _निर्धारित विंडोज कार्यों से लगातार खतरों की खोज के लिए हंटबुक बनाना: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _विंडोज होस्ट पर बैकवर्ड और फॉरवर्ड ट्रैकिंग हंट्स का अभ्यास करना: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _अपनी खुद की Kestrel विश्लेषिकी बनाएं और समुदाय के साथ साझा करें: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Kestrel और SysFlow के साथ संकर क्लाउड में ओपन हंटिंग स्टैक स्थापित करना: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _क्लाउड सैंडबॉक्स में Kestrel आज़माएं: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _securitydatasets.com और Kestrel PowerShell डिऑबफस्केटर के साथ मज़ा: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel डेटा पुनर्प्राप्ति समझाया गया: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/
.. _RSA Conference 2021: https://www.rsaconference.com/Library/presentation/USA/2021/The%20Game%20of%20Cyber%20Threat%20Hunting%20The%20Return%20of%20the%20Fun .. _RSA'21 सत्र रिकॉर्डिंग: https://www.youtube.com/watch?v=-Xb086R0JTk .. _SANS Threat Hunting Summit 2021: https://www.sans.org/blog/a-visual-summary-of-sans-threat-hunting-summit-2021/ .. _SANS'21 सत्र रिकॉर्डिंग: https://www.youtube.com/watch?v=gyY5DAWLwT0 .. _BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#an-open-stack-for-threat-hunting-in-hybrid-cloud-with-connected-observability-25112 .. _Infosec Jupyterthon 2021: https://infosecjupyterthon.com/2021/agenda.html .. _IJ'21 लाइव हंट रिकॉर्डिंग: https://www.youtube.com/embed/nMnHBnYfIaI?start=20557&end=22695 .. _Infosec Jupyterthon 2022: https://infosecjupyterthon.com/2022/agenda.html .. _IJ'22 लाइव हंट रिकॉर्डिंग: https://www.youtube.com/embed/8Mw1yyYkeqM?start=23586&end=26545 .. _SC eSummit on Threat Hunting & Offense Security: https://www.scmagazine.com/esummit/automating-the-hunt-for-advanced-threats .. _Cybersecurity Automation Workshop: http://www.cybersecurityautomationworkshop.org/ .. _Black Hat USA 2024: https://www.blackhat.com/us-24/arsenal/schedule/index.html#kestrel--hunt-for-threats-across-security-data-lakes-39321 .. _Black Hat USA 2023: https://www.blackhat.com/us-23/arsenal/schedule/index.html#identity-threat-hunting-with-kestrel-33662 .. _Black Hat USA 2022: .. _BH'22 रिकॉर्डिंग: .. _Black Hat USA 2022 सत्र रिकॉर्डिंग: .. _BH'22 हंटिंग लैब: .. _Black Hat USA 2022 Kestrel हंटिंग लैब: .. _Black Hat USA 2024 Kestrel हंटिंग लैब: .. _Red Hat Research Quarterly: .. _CNCF Secure AI Summit 2024:
.. _स्लैक आमंत्रण: https://join.slack.com/t/open-cybersecurity/shared_invite/zt-19pliofsm-L7eSSB8yzABM2Pls1nS12w .. _Open Cybersecurity Alliance कार्यक्षेत्र: https://open-cybersecurity.slack.com/ .. _GitHub Issue: https://github.com/opencybersecurityalliance/kestrel-lang/issues .. _योगदान दिशानिर्देश: CONTRIBUTING.rst .. _शासन दस्तावेज़ीकरण: GOVERNANCE.rst .. _Apache License 2.0: LICENSE.md
.. |readthedocs| image:: https://readthedocs.org/projects/kestrel/badge/?version=latest :target: https://kestrel.readthedocs.io/en/latest/?badge=latest :alt: Documentation Status
.. |pypi| image:: https://img.shields.io/pypi/v/kestrel-jupyter :target: https://pypi.python.org/pypi/kestrel-jupyter :alt: Latest Version
.. |downloads| image:: https://img.shields.io/pypi/dm/kestrel-core :target: https://pypistats.org/packages/kestrel-core :alt: PyPI Downloads
.. |codecoverage| image:: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang/branch/develop/graph/badge.svg?token=HM4ax10IW3 :target: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang :alt: Code Coverage
.. |black| image:: https://img.shields.io/badge/code%20style-black-000000.svg :target: https://github.com/psf/black :alt: Code Style: Black
SANS Threat Hunting Summit 2021: [SANS'21 सत्र रिकॉर्डिंग]RSA Conference 2021: [RSA'21 सत्र रिकॉर्डिंग]