.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Kestrel 脅威ハンティング言語
|readthedocs| |pypi| |downloads| |codecoverage| |black|
|
*エンドツーエンドのサイバー脅威ハンティングは通常、複数のデータソース/環境にわたる実行と、ハントフローの任意の場所でのエンリッチメント/ML/可視化ステップを必要とします。
.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Kestrel2 の例
Kestrel は、再利用可能で構成可能、共有可能なハントフローを構築するための抽象化レイヤーを提供することで、サイバー脅威ハンティングを高速にすることを目指した脅威ハンティング言語です。まずはこちらから:
#. Black Hat USA 2024 Kestrel hunting lab_
#. Black Hat USA 2022 Kestrel hunting lab_
#. Black Hat USA 2022 session recording_
Black Hat USA 2024_ に登録CNCF Secure AI Summit 2024_ での Kestrel と AI に関するトークRed Hat Research Quarterly_ (RHRQ) でスケーラブルな Kestrel デプロイメントを学ぶソフトウェア開発者は Python や Swift を書き、それをマシンコードに変換してビジネスロジックを素早くアプリケーションにします。脅威ハンターは Kestrel を書き、脅威仮説を素早くハントフローに変換します。私たちは脅威ハンティングを、カスタマイズされた侵入検知システムをその場で作成するための対話型手順と捉えており、ハントフローは通常のプログラムにおける制御フローに相当します。
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Kestrel の概要。
Kestrel 言語:人間が何をハントするかを表現するための脅威ハンティング言語。
Kestrel ランタイム:どのようにハントするかを扱うマシンインタプリタ。
Kestrel ドキュメント_ にアクセスして Kestrel を学びましょう:
概念と構文を学ぶ:
Kestrel の包括的な紹介_Kestrel の2つの重要な概念_クイズ付きインタラクティブチュートリアル_言語リファレンスブック_自身の環境でハントする:
Kestrel ランタイムのインストール_データソースへの接続方法_Python/Docker で分析ハントステップを実行する方法_API 経由で Kestrel を使用する方法_Kestrel を Docker コンテナとして起動する方法_Kestrel 2 は Black Hat USA 2024_ でデビューします。Kestrel 1 の言語構文を維持しつつ、Kestrel 2 のランタイムを完全に再設計し、エンティティ、属性、関係の表現において、より優れたパフォーマンスとより柔軟な構文を実現しました。
Kestrel 2 の主な機能:
インタプリタではなくジャストインタイムコンパイル
遅延評価と新しい EXPLAIN コマンド
深くネストされたクエリによるデータレイクハウス最適化
STIX に加えて OCSF と OpenTelemetry のエンティティ/属性サポート
Kestrel 2 は現在ベータ版です。詳細は Kestrel ランタイムのインストール_ をご覧ください。
Kestrel ハントブック_: コミュニティが貢献した Kestrel ハントブックKestrel 分析_: コミュニティが貢献した Kestrel 分析Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks_Practicing Backward And Forward Tracking Hunts on A Windows Host_Building Your Own Kestrel Analytics and Sharing With the Community_Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow_Try Kestrel in a Cloud Sandbox_Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator_Kestrel Data Retrieval Explained_トークの概要(詳細は Kestrel ドキュメントのトークページ_ をご覧ください):
Black Hat USA 2024_CNCF Secure AI Summit 2024_Black Hat USA 2023_Infosec Jupyterthon 2022_ [IJ'22 live hunt recording_]Black Hat USA 2022_ [BH'22 recording_ | BH'22 hunting lab_]Cybersecurity Automation Workshop_SC eSummit on Threat Hunting & Offense Security_(無料登録/再生可能)Infosec Jupyterthon 2021_ [IJ'21 live hunt recording_]BlackHat Europe 2021_SANS Threat Hunting Summit 2021: [SANS'21 session recording]RSA Conference 2021: [RSA'21 session recording]Kestrel Slack チャンネルに参加:
Slack 招待_ を取得して Open Cybersecurity Alliance ワークスペース_ に参加
.. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: OCA ロゴ
kestrel チャンネルに参加して質問し、他のハンターと繋がる
言語開発に貢献(Apache License 2.0_):
GitHub Issue_ を作成してバグ報告や新機能の提案コントリビューションガイドライン_ に従ってプルリクエストを送信ガバナンスドキュメント_ を参照ハントブックと分析を共有:
Kestrel ハントブック_Kestrel 分析_.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/
.. _A comprehensive introduction to Kestrel: https://kestrel.readthedocs.io/en/latest/overview/ .. _The two key concepts of Kestrel: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _Interactive tutorial with quiz: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel runtime installation: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _How to connect to your data sources: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _How to execute an analytic hunt step in Python/Docker: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _Language reference book: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _How to use Kestrel via API: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _How to launch Kestrel as a Docker container: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel documentation on talks: https://kestrel.readthedocs.io/en/latest/talks.html
.. _Kestrel huntbook: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel analytics: https://github.com/opencybersecurityalliance/kestrel-analytics
.. _Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Practicing Backward And Forward Tracking Hunts on A Windows Host: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _Building Your Own Kestrel Analytics and Sharing With the Community: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _Try Kestrel in a Cloud Sandbox: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel Data Retrieval Explained: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/