.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Kestrel威胁狩猎语言
|readthedocs| |pypi| |downloads| |codecoverage| |black|
|
*一次端到端的网络威胁狩猎通常需要在多个数据源/环境中执行,并在狩猎流程中的任意位置进行 enrichment/ML/可视化步骤。
.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Kestrel2示例
Kestrel是一种威胁狩猎语言,旨在通过提供一层抽象来构建可重用、可组合和可共享的狩猎流程,从而使网络威胁狩猎变得快速。从以下开始:
#. Black Hat USA 2024 Kestrel 狩猎实验室_
#. Black Hat USA 2022 Kestrel 狩猎实验室_
#. Black Hat USA 2022 会议录像_
Black Hat USA 2024_ 使用Kestrel进行狩猎CNCF Secure AI Summit 2024_ 上的演讲Red Hat Research Quarterly_ 学习可扩展的Kestrel部署(RHRQ)软件开发人员编写Python或Swift而非机器代码,以快速将业务逻辑转化为应用程序。威胁狩猎人员编写Kestrel,以快速将威胁假设转化为狩猎流程。我们将威胁狩猎视为一种交互式过程,用于即时创建定制化的入侵检测系统,而狩猎流程之于狩猎,如同控制流程之于普通程序。
.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Kestrel概述。
Kestrel语言:一种供人类表达狩猎什么的威胁狩猎语言。
Kestrel运行时:处理如何狩猎的机器解释器。
访问 Kestrel文档_ 学习Kestrel:
学习概念与语法:
Kestrel全面介绍_Kestrel的两个关键概念_带测验的交互式教程_语言参考手册_在你的环境中狩猎:
Kestrel运行时安装_如何连接数据源_如何在Python/Docker中执行分析狩猎步骤_如何通过API使用Kestrel_如何以Docker容器方式启动Kestrel_Kestrel 2 在 Black Hat USA 2024_ 首次亮相。在保持Kestrel 1语言语法的基础上,我们完全重新设计了Kestrel 2运行时,以实现更好的性能以及更灵活的实体、属性和关系表示语法。
Kestrel 2的关键特性:
即时编译而非解释执行
惰性求值与新的 EXPLAIN 命令
深度嵌套查询的数据湖仓优化
除STIX外,支持OCSF和OpenTelemetry实体/属性
Kestrel 2目前处于测试阶段,更多信息请访问 Kestrel运行时安装_。
Kestrel狩猎手册_:社区贡献的Kestrel狩猎手册Kestrel分析_:社区贡献的Kestrel分析#. 构建狩猎手册以发现计划性Windows任务中的持久威胁_
#. 在Windows主机上实践向后和向前追踪狩猎_
#. 构建自己的Kestrel分析与社区分享_
#. 使用Kestrel和SysFlow在混合云中部署开放狩猎栈_
#. 在云沙盒中尝试Kestrel_
#. 使用securitydatasets.com与Kestrel PowerShell反混淆工具的乐趣_
#. Kestrel数据检索解释_
演讲摘要(访问 Kestrel演讲文档_ 了解详情):
Black Hat USA 2024_CNCF Secure AI Summit 2024_Black Hat USA 2023_Infosec Jupyterthon 2022_ [IJ'22 实时狩猎录像_]Black Hat USA 2022_ [BH'22 录像_ | BH'22 狩猎实验室_]Cybersecurity Automation Workshop_SC eSummit on Threat Hunting & Offense Security_(免费注册/回放)Infosec Jupyterthon 2021_ [IJ'21 实时狩猎录像_]BlackHat Europe 2021_SANS Threat Hunting Summit 2021: [SANS'21 会议录像]RSA Conference 2021: [RSA'21 会议录像]加入Kestrel Slack频道:
获取 Slack邀请_ 加入 Open Cybersecurity Alliance工作空间_
.. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: OCA标识
加入 kestrel 频道,提问并与其他狩猎者联系
贡献语言开发(Apache License 2.0_):
GitHub Issue_ 报告错误并建议新功能贡献指南_ 提交拉取请求治理文档_ 了解PR合并、发布和漏洞披露分享你的狩猎手册和分析:
Kestrel狩猎手册_Kestrel分析_.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/
.. _A comprehensive introduction to Kestrel: https://kestrel.readthedocs.io/en/latest/overview/ .. _The two key concepts of Kestrel: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _Interactive tutorial with quiz: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel runtime installation: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _How to connect to your data sources: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _How to execute an analytic hunt step in Python/Docker: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _Language reference book: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _How to use Kestrel via API: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _How to launch Kestrel as a Docker container: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel documentation on talks: https://kestrel.readthedocs.io/en/latest/talks.html
.. _Kestrel huntbook: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel analytics: https://github.com/opencybersecurityalliance/kestrel-analytics
.. _Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Practicing Backward And Forward Tracking Hunts on A Windows Host: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _Building Your Own Kestrel Analytics and Sharing With the Community: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _Try Kestrel in a Cloud Sandbox: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel Data Retrieval Explained: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/