{"repo":"activecm/rita-legacy","free":true,"listed":false,"github":"https://github.com/activecm/rita-legacy","clone":"git clone https://github.com/activecm/rita-legacy.git","description":"Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.","language":"Go","stars":2509,"topics":["rita","network-traffic","threat","scanning","offensive-countermeasures","bro-ids","blueteam","security","logs","analytics"],"license":"GPL-3.0","category":"analytics","readme_excerpt":":exclamation: Important Notice :exclamation: This repository has been archived and is no longer maintained. The project has undergone a complete rewrite and significant improvements. The new version of this project can be found here. RITA (Real Intelligence Threat Analytics) (Legacy) If you get value out of RITA and would like to go a step further with hunting automation, futuristic visualizations, and data encrichment take a look at AC-Hunter. Sponsored by Active Countermeasures. --- RITA is an open source framework for network traffic analysis. The framework ingests Zeek Logs in TSV format, and currently supports the following major features: - Beaconing Detection : Search for signs of beaconing behavior in and out of your network - DNS Tunneling Detection Search for signs of DNS based covert channels - Blacklist Checking : Query blacklists to search for suspicious domains and hosts Install Please see our recommended System Requirements document if you wish to use RITA in a production environment. Automated Install RITA provides an install script that works on Ubuntu 20.04 LTS, Debian 11, Security Onion, and CentOS 7. Download the latest install.sh file here and make it executable: chmod +x ./install.sh Then choose one of the following install methods: - sudo ./install.sh will install RITA as well as supported versions of Zeek and MongoDB. This is suitable if you want to get started as quickly as possible or you don't already have Zeek or MongoDB. - sudo ./install.sh --disa","default_branch":null,"files":null,"tree":[],"storefront":"/r/activecm","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/activecm/rita-legacy/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}