Linchakin

RedEye – CISA Developed Open-source Red Team Tool Monitoring C&C Server Activities

 October 18, 2022     No comments   

RedEye – CISA Developed Open-source Red Team Tool Monitoring C&C Server Activities

A new open-source analytical tool dubbed RedEye designed to make it easier for operators to visualize and report activities associated with C2 communication has been released by CISA.

Both the red and blue teams can benefit from RedEye, as it provides an easy way to gauge data, leading to specific decisions that can be made with confidence.

RedEye

A collaborative effort between CISA and DOE’s Pacific Northwest National Laboratory has given birth to this analytical tool. 

EHA

A graphically displayed log of all servers and hosts associated with each campaign can be retrieved by RedEye users by correlating historical records of each campaign log.

In order to view relevant information about a campaign, users can upload campaign data via RedEye to view information such as:-

  • Beacons 
  • Commands

During the process of parsing log files, such as those generated by Cobalt Strike, the tool presents the information in a format that can be easily understood.

As a result, users are able to tag activities displayed within the tool and comment on them. Operators can present findings and workflow to stakeholders using the presentation mode that is available on the RedEye application.

To discover the payload activity analysts can also analyze all the key events in a selected campaign. In addition to using RedEye to check the raw data received after an assessment, blue teams can also use it to understand it better.

This data can be used by them to see the attack path and the compromised hosts to take the appropriate action based on what they have learned.

RedEye offers a wide range of features and all its key features are presented in the below video made by CISA:-

Apart from RedEye, the CISA have also released several other open-source tools like:-

  • Malcom
  • ICS NPP
  • Sparrow

The following major platforms have been tested and proved to be compatible with RedEye:- 

  • Linux (Ubuntu 18 and above, Kali Linux 2020.1 or newer)
  • macOS (El Capitan and above)
  • Windows 7 or newer

Moreover, the CISA’s repository on GitHub hosts the tool, and it is available for download via the repository.

Also Read: Download Secure Web Filtering – Free E-book

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • Over $100,000,000 Lost to Romance Scams in Seven MonthsPeople in the US lost $133,400,000 to romance scams between January 1st and July 31st of 2021, according to the FBI. The average amount lost was in th… Read More
  • What is an RNN (Recurrent Neural Network) in Deep Learning? An RNN (Recurrent Neural Network) is a type of artificial neural network that can process sequential data, recognize patterns and predict the f… Read More
  • 20th Sep - PHP ternary operatorIn this article, we will understand about a PHP ternary operator with the help of various examples. What do you mean by Ternary operator? It is also c… Read More
  • Liquid-Cooled XFX RX 6900 XT Zero WB Could Break 3GHzByAleksandar Kostovic XFX has prepared a water-cooled Radeon RX 6900 XT Zero WB graphics card wit...AMD's Radeon RX 6900 XT already delivers impressive performance, ranking among the best graphics cards (that you still can't easily buy). Part of that… Read More
  • Life in Smart Cities: Your Walk in the Park isn't Private Anymore Smart cities are a promising application of IoT(Internet of Things) that brings technological intelligence to various city municipalities such … Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates