Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
kestrel-lang — Linguagem de caça a ameaças Kestrel: construindo fluxos de caça reutilizáveis, componíveis e compartilháveis em diferentes fontes de dados e inteligência de ameaças. | Kitploit
Ferramentas/GitHubGitHub/opencybersecurityalliance/kestrel-lang
Scripting e AutomaçãoColeta de InformaçõesInteligência de AmeaçasAprendizado e EducaçãoLabs e Prática
GitHubopencybersecurityalliance/kestrel-lang

kestrel-lang

Linguagem de caça a ameaças Kestrel: construindo fluxos de caça reutilizáveis, componíveis e compartilháveis em diferentes fontes de dados e inteligência de ameaças.

Ver Repositório

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
32451há 1 anoRevisado pelo Kitploit

.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Linguagem de Caça a Ameaças Kestrel

|readthedocs| |pypi| |downloads| |codecoverage| |black|

|

Caçar com Consulta/Script Nativo (esquerda) ou Kestrel (direita)?

*Uma caça a ameaças cibernéticas de ponta a ponta geralmente requer execução em múltiplas fontes de dados/ambientes, além de etapas de enriquecimento/ML/visualização em qualquer lugar do fluxo de caça.

.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Exemplo do Kestrel2

O que é Kestrel?

Kestrel é uma linguagem de caça a ameaças que visa tornar a caça a ameaças cibernéticas rápida, fornecendo uma camada de abstração para construir fluxos de caça reutilizáveis, compostos e compartilháveis. Começando com:

#. Black Hat USA 2024 Kestrel hunting lab_ #. Black Hat USA 2022 Kestrel hunting lab_ #. Black Hat USA 2022 session recording_

Notícias

  • Registre-se no Black Hat USA 2024_ para caçar com Kestrel
  • Palestra sobre Kestrel e IA no CNCF Secure AI Summit 2024_
  • Aprenda sobre implantação escalável do Kestrel no Red Hat Research Quarterly_ (RHRQ)

Kestrel em Poucas Palavras

Desenvolvedores de software escrevem Python ou Swift em vez de código de máquina para transformar rapidamente lógica de negócios em aplicativos. Caçadores de ameaças escrevem Kestrel para transformar rapidamente hipóteses de ameaças em fluxos de caça. Vemos a caça a ameaças como um procedimento interativo para criar sistemas de detecção de intrusão personalizados em tempo real, e o fluxo de caça está para as caças assim como o fluxo de controle está para programas comuns.

.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Visão geral do Kestrel.

  • Linguagem Kestrel: uma linguagem de caça a ameaças para um humano expressar o que caçar.

    • expressando o conhecimento de o que em padrões, análises e fluxos de caça.
    • compondo fluxos de caça reutilizáveis a partir de etapas individuais de caça.
    • raciocinando com abstração de representação de dados baseada em entidades amigável ao humano.
    • pensando através de fontes heterogêneas de dados e inteligência de ameaças.
    • aplicando lógica de detecção pública e proprietária existente como etapas analíticas de caça.
    • reutilizando e compartilhando etapas individuais de caça, fluxo de caça e huntbooks completos.
  • Runtime Kestrel: um interpretador de máquina que lida com como caçar.

    • compilando o o que contra instruções específicas da plataforma de caça.
    • executando o código compilado local e remotamente.
    • montando logs e registros brutos em entidades para raciocínio baseado em entidades.
    • armazenando em cache dados intermediários e registros relacionados para resposta rápida.
    • pré-buscando logs e registros relacionados para construção de links entre entidades.
    • definindo interfaces extensíveis para fontes de dados e execução de análises.

Conceitos Básicos e Como Fazer

Visite a documentação do Kestrel_ para aprender Kestrel:

  • Aprenda conceitos e sintaxe:

    • A comprehensive introduction to Kestrel_
    • The two key concepts of Kestrel_
    • Interactive tutorial with quiz_
    • Language reference book_
  • Caça em seu ambiente:

    • Kestrel runtime installation_
    • How to connect to your data sources_
    • How to execute an analytic hunt step in Python/Docker_
    • How to use Kestrel via API_
    • How to launch Kestrel as a Docker container_

Kestrel 2

Kestrel 2 estreia no Black Hat USA 2024_. Embora mantendo a sintaxe da linguagem do Kestrel 1, redesenhamos completamente o runtime do Kestrel 2 para alcançar melhor desempenho e sintaxe mais flexível em relação a representações de entidade, atributo e relação.

Principais recursos do Kestrel 2:

  • Compilação just-in-time em vez de interpretação
  • Avaliação preguiçosa e o novo comando EXPLAIN
  • Otimização de Data Lakehouse com consultas profundamente aninhadas
  • Suporte a entidade/atributo OCSF e OpenTelemetry além de STIX

Kestrel 2 está atualmente em beta, saiba mais em Kestrel runtime installation_.

Huntbooks e Análises do Kestrel

  • Kestrel huntbook_: huntbooks Kestrel contribuídos pela comunidade
  • Kestrel analytics_: análises Kestrel contribuídas pela comunidade

Blogs sobre Caça com Kestrel

#. Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks_ #. Practicing Backward And Forward Tracking Hunts on A Windows Host_ #. Building Your Own Kestrel Analytics and Sharing With the Community_ #. Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow_ #. Try Kestrel in a Cloud Sandbox_ #. Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator_ #. Kestrel Data Retrieval Explained_

Palestras e Demonstrações

Resumo das palestras (visite a documentação do Kestrel sobre palestras_ para mais detalhes):

  • 2024/08 Black Hat USA 2024_
  • 2024/06 CNCF Secure AI Summit 2024_
  • 2023/08 Black Hat USA 2023_
  • 2022/12 Infosec Jupyterthon 2022_ [IJ'22 live hunt recording_]
  • 2022/08 Black Hat USA 2022_ [BH'22 recording_ | BH'22 hunting lab_]
  • 2022/06 Cybersecurity Automation Workshop_
  • 2022/04 SC eSummit on Threat Hunting & Offense Security_ (grátis para registro/reprodução)
  • 2021/12 Infosec Jupyterthon 2021_ [IJ'21 live hunt recording_]
  • 2021/11 BlackHat Europe 2021_

Conectando-se com a Comunidade

  • Junte-se ao canal slack do Kestrel:

    • Obtenha um convite do slack_ para entrar no workspace da Open Cybersecurity Alliance_

      .. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: Logo OCA

    • Entre no canal kestrel para fazer perguntas e se conectar com outros caçadores

  • Contribua para o desenvolvimento da linguagem (Apache License 2.0_):

    • Crie uma Issue no GitHub_ para relatar bugs e sugerir novos recursos
    • Siga o guia de contribuição_ para enviar seu pull request
    • Consulte a documentação de governança_ sobre merge de PR, lançamento e divulgação de vulnerabilidades
  • Compartilhe seu huntbook e análises:

    • Kestrel huntbook_
    • Kestrel analytics_

.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/

.. _A comprehensive introduction to Kestrel: https://kestrel.readthedocs.io/en/latest/overview/ .. _The two key concepts of Kestrel: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _Interactive tutorial with quiz: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel runtime installation: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _How to connect to your data sources: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _How to execute an analytic hunt step in Python/Docker: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _Language reference book: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _How to use Kestrel via API: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _How to launch Kestrel as a Docker container: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel documentation on talks: https://kestrel.readthedocs.io/en/latest/talks.html

.. _Kestrel huntbook: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel analytics: https://github.com/opencybersecurityalliance/kestrel-analytics

.. _Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Practicing Backward And Forward Tracking Hunts on A Windows Host: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _Building Your Own Kestrel Analytics and Sharing With the Community: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _Try Kestrel in a Cloud Sandbox: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel Data Retrieval Explained: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/

.. _RSA Conference 2021: https://www.rsaconference.com/Library/presentation/USA/2021/The%20Game%20of%20Cyber%20Threat%20Hunting%20The%20Return%20of%20the%20Fun .. _RSA'21 session recording: https://www.youtube.com/watch?v=-Xb086R0JTk .. _SANS Threat Hunting Summit 2021: https://www.sans.org/blog/a-visual-summary-of-sans-threat-hunting-summit-2021/ .. _SANS'21 session recording: https://www.youtube.com/watch?v=gyY5DAWLwT0 .. _BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#an-open-stack-for-threat-hunting-in-hybrid-cloud-with-connected-observability-25112 .. _Infosec Jupyterthon 2021: https://infosecjupyterthon.com/2021/agenda.html .. _IJ'21 live hunt recording: https://www.youtube.com/embed/nMnHBnYfIaI?start=20557&end=22695 .. _Infosec Jupyterthon 2022: https://infosecjupyterthon.com/2022/agenda.html .. _IJ'22 live hunt recording: https://www.youtube.com/embed/8Mw1yyYkeqM?start=23586&end=26545 .. _SC eSummit on Threat Hunting & Offense Security: https://www.scmagazine.com/esummit/automating-the-hunt-for-advanced-threats .. _Cybersecurity Automation Workshop: http://www.cybersecurityautomationworkshop.org/ .. _Black Hat USA 2024: https://www.blackhat.com/us-24/arsenal/schedule/index.html#kestrel--hunt-for-threats-across-security-data-lakes-39321 .. _Black Hat USA 2023: https://www.blackhat.com/us-23/arsenal/schedule/index.html#identity-threat-hunting-with-kestrel-33662 .. _Black Hat USA 2022: .. _BH'22 recording: .. _Black Hat USA 2022 session recording: .. _BH'22 hunting lab: .. _Black Hat USA 2022 Kestrel hunting lab: .. _Black Hat USA 2024 Kestrel hunting lab: .. _Red Hat Research Quarterly: .. _CNCF Secure AI Summit 2024:

.. _slack invitation: https://join.slack.com/t/open-cybersecurity/shared_invite/zt-19pliofsm-L7eSSB8yzABM2Pls1nS12w .. _Open Cybersecurity Alliance workspace: https://open-cybersecurity.slack.com/ .. _GitHub Issue: https://github.com/opencybersecurityalliance/kestrel-lang/issues .. _contributing guideline: CONTRIBUTING.rst .. _governance documentation: GOVERNANCE.rst .. _Apache License 2.0: LICENSE.md

.. |readthedocs| image:: https://readthedocs.org/projects/kestrel/badge/?version=latest :target: https://kestrel.readthedocs.io/en/latest/?badge=latest :alt: Documentation Status

.. |pypi| image:: https://img.shields.io/pypi/v/kestrel-jupyter :target: https://pypi.python.org/pypi/kestrel-jupyter :alt: Latest Version

.. |downloads| image:: https://img.shields.io/pypi/dm/kestrel-core :target: https://pypistats.org/packages/kestrel-core :alt: PyPI Downloads

.. |codecoverage| image:: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang/branch/develop/graph/badge.svg?token=HM4ax10IW3 :target: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang :alt: Code Coverage

.. |black| image:: https://img.shields.io/badge/code%20style-black-000000.svg :target: https://github.com/psf/black :alt: Code Style: Black

Baixar ferramenta
  • 2021/10 SANS Threat Hunting Summit 2021: [SANS'21 session recording]
  • 2021/05 RSA Conference 2021: [RSA'21 session recording]
  • https://www.blackhat.com/us-22/arsenal/schedule/index.html#streamlining-and-automating-threat-hunting-with-kestrel-28014
    https://www.youtube.com/watch?v=tf1VLIpFefs
    https://www.youtube.com/watch?v=tf1VLIpFefs
    https://mybinder.org/v2/gh/opencybersecurityalliance/black-hat-us-2022/HEAD?filepath=demo
    https://mybinder.org/v2/gh/opencybersecurityalliance/black-hat-us-2022/HEAD?filepath=demo
    https://github.com/opencybersecurityalliance/black-hat-us-2024
    https://research.redhat.com/blog/article/team-threat-hunting-on-a-container-platform-kestrel-as-a-service/
    https://secureaisummit2024.sched.com/event/1dBWF/elevate-cloud-threat-hunting-with-ai-kenneth-peeples-maya-costantini-red-hat