
Kestrel — язык поиска угроз: создание многократно используемых, компонуемых и распространяемых потоков охоты по различным источникам данных и данным об угрозах.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Язык охоты за угрозами Kestrel
|readthedocs| |pypi| |downloads| |codecoverage| |black|
|
*Полноценная киберразведка обычно требует выполнения в нескольких источниках данных/средах, а также этапов обогащения/ML/визуализации в любом месте huntflow.
.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Пример Kestrel2
Kestrel — это язык охоты за угрозами, предназначенный для того, чтобы сделать охоту за киберугрозами быстрой, предоставляя уровень абстракции для создания повторно используемых, компонуемых и совместно используемых потоков охоты. Начните с:
#. Black Hat USA 2024 Kestrel hunting lab_
#. Black Hat USA 2022 Kestrel hunting lab_
#. Black Hat USA 2022 session recording_
Black Hat USA 2024_, чтобы охотиться с KestrelCNCF Secure AI Summit 2024_Red Hat Research Quarterly_ (RHRQ)Разработчики ПО пишут на Python или Swift, затем на машинном коде, чтобы быстро превратить бизнес-логику в приложения. Охотники за угрозами пишут на Kestrel, чтобы быстро превратить гипотезы об угрозах в поток охоты. Мы рассматриваем охоту за угрозами как интерактивную процедуру создания на лету собственных систем обнаружения вторжений, и поток охоты относится к охотам так же, как поток управления — к обычным программам.
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Обзор Kestrel.
Язык Kestrel: язык охоты за угрозами для того, чтобы человек мог выразить на что охотиться.
Среда выполнения Kestrel: машинный интерпретатор, который занимается как охотиться.
Посетите Kestrel documentation_, чтобы изучить Kestrel:
Изучите концепции и синтаксис:
A comprehensive introduction to Kestrel_The two key concepts of Kestrel_Interactive tutorial with quiz_Language reference book_Охотьтесь в вашей среде:
Kestrel runtime installation_How to connect to your data sources_How to execute an analytic hunt step in Python/Docker_How to use Kestrel via API_How to launch Kestrel as a Docker container_Kestrel 2 дебютирует на Black Hat USA 2024_. Сохраняя синтаксис языка Kestrel 1, мы полностью переработали среду выполнения Kestrel 2 для достижения лучшей производительности и более гибкого синтаксиса в отношении представлений сущностей, атрибутов и отношений.
Ключевые особенности Kestrel 2:
Just-in-time компиляция вместо интерпретации
Ленивые вычисления и новая команда EXPLAIN
Оптимизация Data Lakehouse с глубоко вложенными запросами
Поддержка сущностей/атрибутов OCSF и OpenTelemetry помимо STIX
Kestrel 2 в настоящее время находится в бета-версии, узнайте больше на Kestrel runtime installation_.
Kestrel huntbook_: поисковые книги Kestrel, предоставленные сообществомKestrel analytics_: аналитика Kestrel, предоставленная сообществом#. Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks_
#. Practicing Backward And Forward Tracking Hunts on A Windows Host_
#. Building Your Own Kestrel Analytics and Sharing With the Community_
#. Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow_
#. Try Kestrel in a Cloud Sandbox_
#. Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator_
#. Kestrel Data Retrieval Explained_
Итоги докладов (посетите Kestrel documentation on talks_ для подробностей):
Black Hat USA 2024_CNCF Secure AI Summit 2024_Black Hat USA 2023_Infosec Jupyterthon 2022_ [IJ'22 live hunt recording_]Black Hat USA 2022_ [BH'22 recording_ | BH'22 hunting lab_]Cybersecurity Automation Workshop_SC eSummit on Threat Hunting & Offense Security_ (бесплатная регистрация/воспроизведение)Infosec Jupyterthon 2021_ [IJ'21 live hunt recording_]BlackHat Europe 2021_Присоединяйтесь к Slack-каналу Kestrel:
Получите slack invitation, чтобы присоединиться к Open Cybersecurity Alliance workspace
.. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: Логотип OCA
Присоединяйтесь к каналу kestrel, чтобы задавать вопросы и общаться с другими охотниками
Вносите вклад в развитие языка (Apache License 2.0_):
GitHub Issue_, чтобы сообщить об ошибках и предложить новые функцииcontributing guideline_, чтобы отправить запрос на включение измененийgovernance documentation_ по вопросам слияния PR, выпуска и раскрытия уязвимостейДелитесь своими поисковыми книгами и аналитикой:
Kestrel huntbook_Kestrel analytics_.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/
.. _A comprehensive introduction to Kestrel: https://kestrel.readthedocs.io/en/latest/overview/ .. _The two key concepts of Kestrel: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _Interactive tutorial with quiz: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel runtime installation: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _How to connect to your data sources: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _How to execute an analytic hunt step in Python/Docker: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _Language reference book: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _How to use Kestrel via API: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _How to launch Kestrel as a Docker container: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel documentation on talks: https://kestrel.readthedocs.io/en/latest/talks.html
.. _Kestrel huntbook: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel analytics: https://github.com/opencybersecurityalliance/kestrel-analytics
.. _Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Practicing Backward And Forward Tracking Hunts on A Windows Host: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _Building Your Own Kestrel Analytics and Sharing With the Community: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _Try Kestrel in a Cloud Sandbox: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel Data Retrieval Explained: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/
.. _RSA Conference 2021: https://www.rsaconference.com/Library/presentation/USA/2021/The%20Game%20of%20Cyber%20Threat%20Hunting%20The%20Return%20of%20the%20Fun .. _RSA'21 session recording: https://www.youtube.com/watch?v=-Xb086R0JTk .. _SANS Threat Hunting Summit 2021: https://www.sans.org/blog/a-visual-summary-of-sans-threat-hunting-summit-2021/ .. _SANS'21 session recording: https://www.youtube.com/watch?v=gyY5DAWLwT0 .. _BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#an-open-stack-for-threat-hunting-in-hybrid-cloud-with-connected-observability-25112 .. _Infosec Jupyterthon 2021: https://infosecjupyterthon.com/2021/agenda.html .. _IJ'21 live hunt recording: https://www.youtube.com/embed/nMnHBnYfIaI?start=20557&end=22695 .. _Infosec Jupyterthon 2022: https://infosecjupyterthon.com/2022/agenda.html .. _IJ'22 live hunt recording: https://www.youtube.com/embed/8Mw1yyYkeqM?start=23586&end=26545 .. _SC eSummit on Threat Hunting & Offense Security: https://www.scmagazine.com/esummit/automating-the-hunt-for-advanced-threats .. _Cybersecurity Automation Workshop: http://www.cybersecurityautomationworkshop.org/ .. _Black Hat USA 2024: https://www.blackhat.com/us-24/arsenal/schedule/index.html#kestrel--hunt-for-threats-across-security-data-lakes-39321 .. _Black Hat USA 2023: https://www.blackhat.com/us-23/arsenal/schedule/index.html#identity-threat-hunting-with-kestrel-33662 .. _Black Hat USA 2022: .. _BH'22 recording: .. _Black Hat USA 2022 session recording: .. _BH'22 hunting lab: .. _Black Hat USA 2022 Kestrel hunting lab: .. _Black Hat USA 2024 Kestrel hunting lab: .. _Red Hat Research Quarterly: .. _CNCF Secure AI Summit 2024:
.. _slack invitation: https://join.slack.com/t/open-cybersecurity/shared_invite/zt-19pliofsm-L7eSSB8yzABM2Pls1nS12w .. _Open Cybersecurity Alliance workspace: https://open-cybersecurity.slack.com/ .. _GitHub Issue: https://github.com/opencybersecurityalliance/kestrel-lang/issues .. _contributing guideline: CONTRIBUTING.rst .. _governance documentation: GOVERNANCE.rst .. _Apache License 2.0: LICENSE.md
.. |readthedocs| image:: https://readthedocs.org/projects/kestrel/badge/?version=latest :target: https://kestrel.readthedocs.io/en/latest/?badge=latest :alt: Documentation Status
.. |pypi| image:: https://img.shields.io/pypi/v/kestrel-jupyter :target: https://pypi.python.org/pypi/kestrel-jupyter :alt: Latest Version
.. |downloads| image:: https://img.shields.io/pypi/dm/kestrel-core :target: https://pypistats.org/packages/kestrel-core :alt: PyPI Downloads
.. |codecoverage| image:: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang/branch/develop/graph/badge.svg?token=HM4ax10IW3 :target: https://codecov.io/gh/opencybersecurityalliance/kestrel-lang :alt: Code Coverage
.. |black| image:: https://img.shields.io/badge/code%20style-black-000000.svg :target: https://github.com/psf/black :alt: Code Style: Black
SANS Threat Hunting Summit 2021: [SANS'21 session recording]RSA Conference 2021: [RSA'21 session recording]