
Kestrel 위협 사냥 언어: 재사용 가능하고, 구성 가능하며, 공유 가능한 헌트플로우를 다양한 데이터 소스와 위협 인텔리전스 전반에 걸쳐 구축합니다.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Kestrel 위협 헌팅 언어
|readthedocs| |pypi| |downloads| |codecoverage| |black|
|
*종단간 사이버 위협 헌트는 일반적으로 여러 데이터 소스/환경에서의 실행과 헌트플로우 어디서든 강화/ML/시각화 단계를 필요로 합니다.
.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Kestrel2 예시
Kestrel은 재사용 가능하고, 구성 가능하며, 공유 가능한 헌트 흐름을 구축하기 위한 추상화 계층을 제공하여 사이버 위협 헌팅을 빠르게 만드는 것을 목표로 하는 위협 헌팅 언어입니다. 다음으로 시작:
#. Black Hat USA 2024 Kestrel 헌팅 랩_
#. Black Hat USA 2022 Kestrel 헌팅 랩_
#. Black Hat USA 2022 세션 녹화_
Black Hat USA 2024_에 등록하세요CNCF Secure AI Summit 2024_에서 Kestrel 및 AI 토크Red Hat Research Quarterly_ (RHRQ)에서 확장 가능한 Kestrel 배포 알아보기소프트웨어 개발자는 Python 또는 Swift를 작성하여 (기계어가 아닌) 비즈니스 로직을 애플리케이션으로 빠르게 전환합니다. 위협 헌터는 Kestrel을 작성하여 위협 가설을 헌트 흐름으로 빠르게 전환합니다. 우리는 위협 헌팅을 맞춤형 침입 탐지 시스템을 즉석에서 생성하는 대화형 절차로 보며, 헌트 흐름은 일반 프로그램의 제어 흐름과 같습니다.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Kestrel 개요.
Kestrel 언어: 위협 헌팅 언어로서 인간이 무엇을 헌트할지 표현합니다.
Kestrel 런타임: 헌트 방법을 처리하는 기계 인터프리터입니다.
Kestrel을 배우려면 Kestrel 문서_를 방문하세요:
개념 및 구문 배우기:
Kestrel 종합 소개_Kestrel의 두 가지 핵심 개념_퀴즈가 포함된 대화형 튜토리얼_언어 참조서_사용자 환경에서 헌트:
Kestrel 런타임 설치_데이터 소스 연결 방법_Python/Docker에서 분석 헌트 단계 실행 방법_API를 통해 Kestrel 사용 방법_Kestrel을 Docker 컨테이너로 실행하는 방법_Kestrel 2는 Black Hat USA 2024_에서 처음 선보입니다. Kestrel 1의 언어 구문을 유지하면서도 엔티티, 속성 및 관계 표현에 대해 더 나은 성능과 더 유연한 구문을 달성하기 위해 Kestrel 2 런타임을 완전히 재설계했습니다.
Kestrel 2의 주요 기능:
해석 대신 적시 컴파일 (Just-in-time compilation)
지연 평가 및 새로운 EXPLAIN 명령
깊게 중첩된 쿼리를 통한 Data Lakehouse 최적화
STIX 외에도 OCSF 및 OpenTelemetry 엔티티/속성 지원
Kestrel 2는 현재 베타 버전입니다. 자세한 내용은 Kestrel 런타임 설치_에서 확인하세요.
Kestrel 헌트북_: 커뮤니티 기여 Kestrel 헌트북Kestrel 분석_: 커뮤니티 기여 Kestrel 분석#. 예약된 Windows 작업에서 지속적 위협을 발견하는 헌트북 구축_
#. Windows 호스트에서 역방향 및 순방향 추적 헌트 연습_
#. 자체 Kestrel 분석 구축 및 커뮤니티와 공유_
#. Kestrel 및 SysFlow를 사용한 하이브리드 클라우드의 오픈 헌팅 스택 설정_
#. 클라우드 샌드박스에서 Kestrel 사용해보기_
#. securitydatasets.com과 Kestrel PowerShell 난독 해제 도구를 활용한 재미_
#. Kestrel 데이터 검색 설명_
토크 요약 (자세한 내용은 Kestrel 토크 문서_ 참조):
Black Hat USA 2024_CNCF Secure AI Summit 2024_Black Hat USA 2023_Infosec Jupyterthon 2022_ [IJ'22 라이브 헌트 녹화_]Black Hat USA 2022_ [BH'22 녹화_ | BH'22 헌팅 랩_]Cybersecurity Automation Workshop_SC eSummit on Threat Hunting & Offense Security_ (등록/재생 무료)Infosec Jupyterthon 2021_ [IJ'21 라이브 헌트 녹화_]BlackHat Europe 2021_Kestrel 슬랙 채널 참여:
Open Cybersecurity Alliance 워크스페이스에 가입하기 위해 슬랙 초대 받기
.. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: OCA 로고
kestrel 채널에 가입하여 질문하고 다른 헌터들과 소통
언어 개발에 기여 (Apache License 2.0_):
GitHub 이슈_를 생성하여 버그 보고 및 새 기능 제안기여 가이드라인_을 따라 풀 리퀘스트 제출거버넌스 문서_ 참조헌트북 및 분석 공유:
Kestrel 헌트북_Kestrel 분석_.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel 문서: https://kestrel.readthedocs.io/
.. _Kestrel 종합 소개: https://kestrel.readthedocs.io/en/latest/overview/ .. _Kestrel의 두 가지 핵심 개념: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _퀴즈가 포함된 대화형 튜토리얼: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel 런타임 설치: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _데이터 소스 연결 방법: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _Python/Docker에서 분석 헌트 단계 실행 방법: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _언어 참조서: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _API를 통해 Kestrel 사용 방법: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _Kestrel을 Docker 컨테이너로 실행하는 방법: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel 토크 문서: https://kestrel.readthedocs.io/en/latest/talks.html
.. _Kestrel 헌트북: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel 분석: https://github.com/opencybersecurityalliance/kestrel-analytics
.. _예약된 Windows 작업에서 지속적 위협을 발견하는 헌트북 구축: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Windows 호스트에서 역방향 및 순방향 추적 헌트 연습: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _자체 Kestrel 분석 구축 및 커뮤니티와 공유: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Kestrel 및 SysFlow를 사용한 하이브리드 클라우드의 오픈 헌팅 스택 설정: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _클라우드 샌드박스에서 Kestrel 사용해보기: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _securitydatasets.com과 Kestrel PowerShell 난독 해제 도구를 활용한 재미: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel 데이터 검색 설명: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/
.. _RSA Conference 2021: https://www.rsaconference.com/Library/presentation/USA/2021/The%20Game%20of%20Cyber%20Threat%20Hunting%20The%20Return%20of%20the%20Fun .. _RSA'21 session recording: https://www.youtube.com/watch?v=-Xb086R0JTk .. _SANS Threat Hunting Summit 2021: https://www.sans.org/blog/a-visual-summary-of-sans-threat-hunting-summit-2021/ .. _SANS'21 session recording: https://www.youtube.com/watch?v=gyY5DAWLwT0 .. _BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#an-open-stack-for-threat-hunting-in-hybrid-cloud-with-connected-observability-25112 .. _Infosec Jupyterthon 2021: https://infosecjupyterthon.com/2021/agenda.html .. _IJ'21 라이브 헌트 녹화: https://www.youtube.com/embed/nMnHBnYfIaI?start=20557&end=22695 .. _Infosec Jupyterthon 2022: https://infosecjupyterthon.com/2022/agenda.html .. _IJ'22 라이브 헌트 녹화: https://www.youtube.com/embed/8Mw1yyYkeqM?start=23586&end=26545 .. _SC eSummit on Threat Hunting & Offense Security: https://www.scmagazine.com/esummit/automating-the-hunt-for-advanced-threats .. _Cybersecurity Automation Workshop: http://www.cybersecurityautomationworkshop.org/ .. _Black Hat USA 2024: https://www.blackhat.com/us-24/arsenal/schedule/index.html#kestrel--hunt-for-threats-across-security-data-lakes-39321 .. _Black Hat USA 2023: https://www.blackhat.com/us-23/arsenal/schedule/index.html#identity-threat-hunting-with-kestrel-33662 .. _Black Hat USA 2022: https://www.blackhat.com/us-22/arsenal/schedule/index.html#streamlining-and-automating-threat-hunting-with-kestrel-28014 .. _BH'22 녹화: .. _Black Hat USA 2022 세션 녹화: .. _BH'22 헌팅 랩: .. _Black Hat USA 2022 Kestrel 헌팅 랩: .. _Black Hat USA 2024 Kestrel 헌팅 랩: .. _Red Hat Research Quarterly: .. _CNCF Secure AI Summit 2024:
.. _슬랙 초대: https://join.slack.com/t/open-cybersecurity/shared_invite/zt-19pliofsm-L7eSSB8yzABM2Pls1nS12w .. _Open Cybersecurity Alliance 워크스페이스: https://open-cybersecurity.slack.com/ .. _GitHub 이슈: https://github.com/opencybersecurityalliance/kestrel-lang/issues .. _기여 가이드라인: CONTRIBUTING.rst .. _거버넌스 문서: GOVERNANCE.rst .. _Apache License 2.0: LICENSE.md
.. |readthedocs| image:: https://readthedocs.org/projects/kestrel/badge/?version=latest :target: https://kestrel.readthedocs.io/en/latest/?badge=latest :alt: 문서 상태
.. |pypi| image:: https://img.shields.io/pypi/v/kestrel-jupyter :target: https://pypi.python.org/pypi/kestrel-jupyter :alt: 최신 버전
.. |downloads| image:: https://img.shields.io/pypi/dm/kestrel-core :target: https://pypistats.org/packages/kestrel-core :alt: PyPI 다운로드 수
.. |codecoverage| image:: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang/branch/develop/graph/badge.svg?token=HM4ax10IW3 :target: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang :alt: 코드 커버리지
.. |black| image:: https://img.shields.io/badge/code%20style-black-000000.svg :target: https://github.com/psf/black :alt: 코드 스타일: Black
SANS Threat Hunting Summit 2021: [SANS'21 세션 녹화]RSA Conference 2021: [RSA'21 세션 녹화]