
Kestrel threat hunting language: costruire huntflows riutilizzabili, componibili e condivisibili attraverso diverse fonti di dati e threat intel.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Linguaggio di Threat Hunting Kestrel
|readthedocs| |pypi| |downloads| |codecoverage| |black|
|
*Una caccia alle minacce end-to-end richiede solitamente esecuzione su più origini dati/ambienti più fasi di arricchimento/ML/visualizzazione in qualsiasi punto del flusso di caccia.
.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Esempio Kestrel 2
Kestrel è un linguaggio di threat hunting che mira a rendere la caccia alle minacce informatiche veloce fornendo uno strato di astrazione per costruire flussi di caccia riutilizzabili, componibili e condivisibili. A partire da:
#. Black Hat USA 2024 Kestrel hunting lab_
#. Black Hat USA 2022 Kestrel hunting lab_
#. Black Hat USA 2022 session recording_
Black Hat USA 2024_ per cacciare con KestrelCNCF Secure AI Summit 2024_Red Hat Research Quarterly_ (RHRQ)Gli sviluppatori scrivono Python o Swift, non codice macchina, per trasformare rapidamente la logica di business in applicazioni. I cacciatori di minacce scrivono Kestrel per trasformare rapidamente le ipotesi di minaccia in flussi di caccia. Vediamo la caccia alle minacce come una procedura interattiva per creare sistemi di rilevamento delle intrusioni personalizzati al volo, e il flusso di caccia sta alle cacce come il flusso di controllo sta ai programmi ordinari.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Panoramica di Kestrel.
Linguaggio Kestrel: un linguaggio di threat hunting per un essere umano per esprimere cosa cacciare.
Runtime Kestrel: un interprete macchina che gestisce come cacciare.
Visita la documentazione di Kestrel_ per imparare Kestrel:
Impara concetti e sintassi:
A comprehensive introduction to Kestrel_The two key concepts of Kestrel_Interactive tutorial with quiz_Language reference book_Caccia nel tuo ambiente:
Kestrel runtime installation_How to connect to your data sources_How to execute an analytic hunt step in Python/Docker_How to use Kestrel via API_How to launch Kestrel as a Docker container_Kestrel 2 debutta al Black Hat USA 2024_. Pur mantenendo la sintassi del linguaggio di Kestrel 1, abbiamo riprogettato completamente il runtime di Kestrel 2 per ottenere prestazioni migliori e una sintassi più flessibile per quanto riguarda le rappresentazioni di entità, attributi e relazioni.
Caratteristiche principali di Kestrel 2:
Compilazione Just-in-time invece di interpretazione
Valutazione lazy e il nuovo comando EXPLAIN
Ottimizzazione del Data Lakehouse con query profondamente annidate
Supporto di entità/attributi OCSF e OpenTelemetry oltre a STIX
Kestrel 2 è attualmente in beta, scopri di più su Kestrel runtime installation_.
Kestrel huntbook_: huntbook Kestrel contribuiti dalla comunitàKestrel analytics_: analitiche Kestrel contribuite dalla comunità#. Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks_
#. Practicing Backward And Forward Tracking Hunts on A Windows Host_
#. Building Your Own Kestrel Analytics and Sharing With the Community_
#. Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow_
#. Try Kestrel in a Cloud Sandbox_
#. Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator_
#. Kestrel Data Retrieval Explained_
Riepilogo degli interventi (visita la documentazione di Kestrel sugli interventi_ per i dettagli):
Black Hat USA 2024_CNCF Secure AI Summit 2024_Black Hat USA 2023_Infosec Jupyterthon 2022_ [IJ'22 live hunt recording_]Black Hat USA 2022_ [BH'22 recording_ | BH'22 hunting lab_]Cybersecurity Automation Workshop_SC eSummit on Threat Hunting & Offense Security_ (free to register/playback)Infosec Jupyterthon 2021_ [IJ'21 live hunt recording_]BlackHat Europe 2021_Unisciti al canale Slack di Kestrel:
Ottieni un invito Slack_ per unirti allo spazio di lavoro Open Cybersecurity Alliance_
.. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: Logo OCA
Unisciti al canale kestrel per fare domande e connetterti con altri cacciatori
Contribuisci allo sviluppo del linguaggio (Apache License 2.0_):
GitHub Issue_ per segnalare bug e suggerire nuove funzionalitàguida al contributo_ per inviare la tua pull requestdocumentazione di governance_ per quanto riguarda merge delle PR, rilascio e divulgazione delle vulnerabilitàCondividi il tuo huntbook e le tue analitiche:
Kestrel huntbook_Kestrel analytics_.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/
.. _A comprehensive introduction to Kestrel: https://kestrel.readthedocs.io/en/latest/overview/ .. _The two key concepts of Kestrel: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _Interactive tutorial with quiz: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel runtime installation: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _How to connect to your data sources: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _How to execute an analytic hunt step in Python/Docker: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _Language reference book: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _How to use Kestrel via API: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _How to launch Kestrel as a Docker container: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel documentation on talks: https://kestrel.readthedocs.io/en/latest/talks.html
.. _Kestrel huntbook: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel analytics: https://github.com/opencybersecurityalliance/kestrel-analytics
.. _Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Practicing Backward And Forward Tracking Hunts on A Windows Host: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _Building Your Own Kestrel Analytics and Sharing With the Community: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _Try Kestrel in a Cloud Sandbox: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel Data Retrieval Explained: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/
.. _RSA Conference 2021: https://www.rsaconference.com/Library/presentation/USA/2021/The%20Game%20of%20Cyber%20Threat%20Hunting%20The%20Return%20of%20the%20Fun .. _RSA'21 session recording: https://www.youtube.com/watch?v=-Xb086R0JTk .. _SANS Threat Hunting Summit 2021: https://www.sans.org/blog/a-visual-summary-of-sans-threat-hunting-summit-2021/ .. _SANS'21 session recording: https://www.youtube.com/watch?v=gyY5DAWLwT0 .. _BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#an-open-stack-for-threat-hunting-in-hybrid-cloud-with-connected-observability-25112 .. _Infosec Jupyterthon 2021: https://infosecjupyterthon.com/2021/agenda.html .. _IJ'21 live hunt recording: https://www.youtube.com/embed/nMnHBnYfIaI?start=20557&end=22695 .. _Infosec Jupyterthon 2022: https://infosecjupyterthon.com/2022/agenda.html .. _IJ'22 live hunt recording: https://www.youtube.com/embed/8Mw1yyYkeqM?start=23586&end=26545 .. _SC eSummit on Threat Hunting & Offense Security: https://www.scmagazine.com/esummit/automating-the-hunt-for-advanced-threats .. _Cybersecurity Automation Workshop: http://www.cybersecurityautomationworkshop.org/ .. _Black Hat USA 2024: https://www.blackhat.com/us-24/arsenal/schedule/index.html#kestrel--hunt-for-threats-across-security-data-lakes-39321 .. _Black Hat USA 2023: https://www.blackhat.com/us-23/arsenal/schedule/index.html#identity-threat-hunting-with-kestrel-33662 .. _Black Hat USA 2022: .. _BH'22 recording: .. _Black Hat USA 2022 session recording: .. _BH'22 hunting lab: .. _Black Hat USA 2022 Kestrel hunting lab: .. _Black Hat USA 2024 Kestrel hunting lab: .. _Red Hat Research Quarterly: .. _CNCF Secure AI Summit 2024:
.. _slack invitation: https://join.slack.com/t/open-cybersecurity/shared_invite/zt-19pliofsm-L7eSSB8yzABM2Pls1nS12w .. _Open Cybersecurity Alliance workspace: https://open-cybersecurity.slack.com/ .. _GitHub Issue: https://github.com/opencybersecurityalliance/kestrel-lang/issues .. _contributing guideline: CONTRIBUTING.rst .. _governance documentation: GOVERNANCE.rst .. _Apache License 2.0: LICENSE.md
.. |readthedocs| image:: https://readthedocs.org/projects/kestrel/badge/?version=latest :target: https://kestrel.readthedocs.io/en/latest/?badge=latest :alt: Documentation Status
.. |pypi| image:: https://img.shields.io/pypi/v/kestrel-jupyter :target: https://pypi.python.org/pypi/kestrel-jupyter :alt: Latest Version
.. |downloads| image:: https://img.shields.io/pypi/dm/kestrel-core :target: https://pypistats.org/packages/kestrel-core :alt: PyPI Downloads
.. |codecoverage| image:: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang/branch/develop/graph/badge.svg?token=HM4ax10IW3 :target: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang :alt: Code Coverage
.. |black| image:: https://img.shields.io/badge/code%20style-black-000000.svg :target: https://github.com/psf/black :alt: Code Style: Black
SANS Threat Hunting Summit 2021: [SANS'21 session recording]RSA Conference 2021: [RSA'21 session recording]