Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
kestrel-lang — Kestrel威胁狩猎语言:在不同数据源和威胁情报之间构建可重用、可组合、可共享的狩猎流程 | Kitploit
工具/GitHubGitHub/opencybersecurityalliance/kestrel-lang
脚本与自动化信息收集威胁情报学习与教育实验室与实践
GitHubopencybersecurityalliance/kestrel-lang

kestrel-lang

Kestrel威胁狩猎语言:在不同数据源和威胁情报之间构建可重用、可组合、可共享的狩猎流程

查看仓库
32451152年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/logo/logo_w_text.png :width: 460 :alt: Kestrel威胁狩猎语言

|readthedocs| |pypi| |downloads| |codecoverage| |black|

|

使用原生查询/脚本(左)还是Kestrel(右)进行狩猎?

*一次端到端的网络威胁狩猎通常需要在多个数据源/环境中执行,并在狩猎流程中的任意位置进行 enrichment/ML/可视化步骤。

.. image:: https://raw.githubusercontent.com/opencybersecurityalliance/data-bucket-kestrel/main/images/kestrel2_example.png :alt: Kestrel2示例

什么是Kestrel?

Kestrel是一种威胁狩猎语言,旨在通过提供一层抽象来构建可重用、可组合和可共享的狩猎流程,从而使网络威胁狩猎变得快速。从以下开始:

#. Black Hat USA 2024 Kestrel 狩猎实验室_ #. Black Hat USA 2022 Kestrel 狩猎实验室_ #. Black Hat USA 2022 会议录像_

新闻

  • 注册 Black Hat USA 2024_ 使用Kestrel进行狩猎
  • Kestrel与AI在 CNCF Secure AI Summit 2024_ 上的演讲
  • 在 Red Hat Research Quarterly_ 学习可扩展的Kestrel部署(RHRQ)

Kestrel简介

软件开发人员编写Python或Swift而非机器代码,以快速将业务逻辑转化为应用程序。威胁狩猎人员编写Kestrel,以快速将威胁假设转化为狩猎流程。我们将威胁狩猎视为一种交互式过程,用于即时创建定制化的入侵检测系统,而狩猎流程之于狩猎,如同控制流程之于普通程序。

.. image:: https://github.com/opencybersecurityalliance/kestrel-lang/raw/develop/docs/images/overview.png :width: 100% :alt: Kestrel概述。

  • Kestrel语言:一种供人类表达狩猎什么的威胁狩猎语言。

    • 以模式、分析和狩猎流程表达什么的知识。
    • 从单个狩猎步骤组合成可重用的狩猎流程。
    • 通过人类友好的基于实体的数据抽象表示进行推理。
    • 跨越异构数据和威胁情报源进行思考。
    • 应用现有的公开和专有检测逻辑作为分析狩猎步骤。
    • 重用和共享单个狩猎步骤、狩猎流程以及整个狩猎手册。
  • Kestrel运行时:处理如何狩猎的机器解释器。

    • 将什么编译为针对特定狩猎平台的指令。
    • 在本地和远程执行编译后的代码。
    • 将原始日志和记录组装成实体,用于基于实体的推理。
    • 缓存中间数据和相关记录,以实现快速响应。
    • 预取相关日志和记录,用于构建实体之间的链接。
    • 定义可扩展的数据源和分析执行接口。

基本概念与操作指南

访问 Kestrel文档_ 学习Kestrel:

  • 学习概念与语法:

    • Kestrel全面介绍_
    • Kestrel的两个关键概念_
    • 带测验的交互式教程_
    • 语言参考手册_
  • 在你的环境中狩猎:

    • Kestrel运行时安装_
    • 如何连接数据源_
    • 如何在Python/Docker中执行分析狩猎步骤_
    • 如何通过API使用Kestrel_
    • 如何以Docker容器方式启动Kestrel_

Kestrel 2

Kestrel 2 在 Black Hat USA 2024_ 首次亮相。在保持Kestrel 1语言语法的基础上,我们完全重新设计了Kestrel 2运行时,以实现更好的性能以及更灵活的实体、属性和关系表示语法。

Kestrel 2的关键特性:

  • 即时编译而非解释执行

  • 惰性求值与新的 EXPLAIN 命令

  • 深度嵌套查询的数据湖仓优化

  • 除STIX外,支持OCSF和OpenTelemetry实体/属性

Kestrel 2目前处于测试阶段,更多信息请访问 Kestrel运行时安装_。

Kestrel狩猎手册与分析

  • Kestrel狩猎手册_:社区贡献的Kestrel狩猎手册
  • Kestrel分析_:社区贡献的Kestrel分析

Kestrel狩猎博客

#. 构建狩猎手册以发现计划性Windows任务中的持久威胁_ #. 在Windows主机上实践向后和向前追踪狩猎_ #. 构建自己的Kestrel分析与社区分享_ #. 使用Kestrel和SysFlow在混合云中部署开放狩猎栈_ #. 在云沙盒中尝试Kestrel_ #. 使用securitydatasets.com与Kestrel PowerShell反混淆工具的乐趣_ #. Kestrel数据检索解释_

演讲与演示

演讲摘要(访问 Kestrel演讲文档_ 了解详情):

  • 2024/08 Black Hat USA 2024_
  • 2024/06 CNCF Secure AI Summit 2024_
  • 2023/08 Black Hat USA 2023_
  • 2022/12 Infosec Jupyterthon 2022_ [IJ'22 实时狩猎录像_]
  • 2022/08 Black Hat USA 2022_ [BH'22 录像_ | BH'22 狩猎实验室_]
  • 2022/06 Cybersecurity Automation Workshop_
  • 2022/04 SC eSummit on Threat Hunting & Offense Security_(免费注册/回放)
  • 2021/12 Infosec Jupyterthon 2021_ [IJ'21 实时狩猎录像_]
  • 2021/11 BlackHat Europe 2021_
  • 2021/10 SANS Threat Hunting Summit 2021: [SANS'21 会议录像]
  • 2021/05 RSA Conference 2021: [RSA'21 会议录像]

与社区连接

  • 加入Kestrel Slack频道:

    • 获取 Slack邀请_ 加入 Open Cybersecurity Alliance工作空间_

      .. image:: https://opencyberallia.wpengine.com/wp-content/uploads/2022/03/OCA-logo-e1646689234325.png :width: 20% :alt: OCA标识

    • 加入 kestrel 频道,提问并与其他狩猎者联系

  • 贡献语言开发(Apache License 2.0_):

    • 创建 GitHub Issue_ 报告错误并建议新功能
    • 遵循 贡献指南_ 提交拉取请求
    • 参考 治理文档_ 了解PR合并、发布和漏洞披露
  • 分享你的狩猎手册和分析:

    • Kestrel狩猎手册_
    • Kestrel分析_

.. _Kestrel live tutorial in a cloud sandbox: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel documentation: https://kestrel.readthedocs.io/

.. _A comprehensive introduction to Kestrel: https://kestrel.readthedocs.io/en/latest/overview/ .. _The two key concepts of Kestrel: https://kestrel.readthedocs.io/en/latest/language/tac.html#key-concepts .. _Interactive tutorial with quiz: https://mybinder.org/v2/gh/opencybersecurityalliance/kestrel-huntbook/HEAD?filepath=tutorial .. _Kestrel runtime installation: https://kestrel.readthedocs.io/en/latest/installation/runtime.html .. _How to connect to your data sources: https://kestrel.readthedocs.io/en/latest/installation/datasource.html .. _How to execute an analytic hunt step in Python/Docker: https://kestrel.readthedocs.io/en/latest/installation/analytics.html .. _Language reference book: https://kestrel.readthedocs.io/en/latest/language/commands.html .. _How to use Kestrel via API: https://kestrel.readthedocs.io/en/latest/source/kestrel.session.html .. _How to launch Kestrel as a Docker container: https://kestrel.readthedocs.io/en/latest/deployment/ .. _Kestrel documentation on talks: https://kestrel.readthedocs.io/en/latest/talks.html

.. _Kestrel huntbook: https://github.com/opencybersecurityalliance/kestrel-huntbook .. _Kestrel analytics: https://github.com/opencybersecurityalliance/kestrel-analytics

.. _Building a Huntbook to Discover Persistent Threats from Scheduled Windows Tasks: https://opencybersecurityalliance.org/huntbook-persistent-threat-discovery-kestrel/ .. _Practicing Backward And Forward Tracking Hunts on A Windows Host: https://opencybersecurityalliance.org/backward-and-forward-tracking-hunts-on-a-windows-host/ .. _Building Your Own Kestrel Analytics and Sharing With the Community: https://opencybersecurityalliance.org/kestrel-custom-analytics/ .. _Setting Up The Open Hunting Stack in Hybrid Cloud With Kestrel and SysFlow: https://opencybersecurityalliance.org/kestrel-sysflow-open-hunting-stack/ .. _Try Kestrel in a Cloud Sandbox: https://opencybersecurityalliance.org/try-kestrel-in-a-cloud-sandbox/ .. _Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator: https://opencybersecurityalliance.org/fun-with-securitydatasets-com-and-the-kestrel-powershell-deobfuscator/ .. _Kestrel Data Retrieval Explained: https://opencybersecurityalliance.org/kestrel-data-retrieval-explained/

下载工具