Please enable JavaScript.
Coggle requires JavaScript to display documents.
RITA (Real Intelligence Threat Analytics) - Enterprise Network Based…
RITA (Real Intelligence Threat Analytics) - Enterprise Network Based Threat Hunting (Linux)
Introduction
What is RITA
Full Form
Real Intelligence Threat Analytics
Purpose
Analyze network metadata
Detect attacker behavior
Detect Command and Control (C2)
Detect beaconing
Detect lateral movement
Detect long-term persistence
Developed By
Active Countermeasures
Works With
Zeek
Bro (Old name of Zeek)
Suricata
PCAP converted to Zeek logs
Does Not
Capture packets
Replace IDS
Replace SIEM
Instead
Analyzes existing network logs
Enterprise Threat Hunting Concept
Threat Hunting
Definition
Proactively search for attackers already inside the network
Goal
Find threats missed by alerts
Discover unknown attacks
Difference
Incident Response
React after alert
Threat Hunting
Search before alert
Types
Structured Hunting
Intelligence Driven Hunting
Hypothesis Driven Hunting
Data Driven Hunting
Network Visibility
Data Sources
Zeek Logs
Suricata Logs
Firewall Logs
Proxy Logs
DNS Logs
DHCP Logs
VPN Logs
NetFlow
IPFIX
Packet Capture
Why Network Metadata
Lightweight
Long retention
Easy searching
Shows attacker behavior
Enterprise Architecture
Internet
Firewall
IDS
Suricata
Snort
Network TAP
Copies traffic
SPAN Port
Mirror switch traffic
Zeek Sensor
Generates logs
RITA Server
Imports Zeek logs
Stores database
Detects threats
SIEM
Elastic
Splunk
Wazuh
Microsoft Sentinel
SOC Analysts
Incident Response Team
RITA Workflow
Capture Network Traffic
Generate Zeek Logs
Import Logs into RITA
Build Database
Analyze Metadata
Detect Beaconing
Detect Long Connections
Detect DNS Tunnels
Detect Rare Connections
Detect Lateral Movement
Generate Reports
Investigate
Contain
Eradicate
Recover
Installation (Linux)
Operating Systems
Ubuntu
Debian
Rocky Linux
AlmaLinux
RHEL
Update System
sudo apt update
sudo apt upgrade
Install Dependencies
MongoDB
Zeek
Git
Go Language
Verify
zeek --version
mongo --version
go version
Typical Directories
/opt/
/usr/local/bin/
/etc/
/var/log/
/var/lib/
Zeek
Previous Name
Bro IDS
Purpose
Network Security Monitoring
Generates Logs
conn.log
dns.log
http.log
ssl.log
files.log
notice.log
weird.log
smb.log
kerberos.log
ntlm.log
Default Log Path
/opt/zeek/logs/current/
Important Files
conn.log
All network connections
dns.log
DNS requests
http.log
HTTP traffic
ssl.log
TLS connections
notice.log
Security notices
Useful Commands
zeekctl status
zeekctl deploy
zeekctl check
zeekctl diag
RITA Database
Backend
MongoDB
Purpose
Store imported metadata
Collections
Connections
DNS
Hosts
Beacons
Long Connections
Database Location
/var/lib/mongodb/
Importing Data
Zeek Logs
conn.log
dns.log
Example Workflow
Import logs
Create database
Run analysis
Generate reports
Detection Techniques
Beaconing Detection
Definition
Malware contacting C2 server repeatedly
Indicators
Same destination
Fixed interval
Small packets
Long duration
Command and Control
Full Form
C2
Purpose
Remote attacker controls malware
Indicators
Repeated callbacks
Encrypted traffic
Regular timing
Long Connections
Persistent TCP sessions
Reverse shells
Malware tunnels
DNS Tunneling
Definition
Sending data inside DNS queries
Indicators
Long domain names
High entropy
Large TXT records
Rare Connections
New countries
Rare IP addresses
Unknown domains
Lateral Movement
Definition
Attacker moving between internal hosts
Indicators
SMB
RDP
SSH
WinRM
PsExec
WMI
Data Exfiltration
Definition
Data leaving organization
Indicators
Large uploads
Cloud storage
FTP
SCP
HTTPS
Internal Reconnaissance
Port scanning
Host discovery
Service enumeration
Enterprise Threat Hunting Techniques
Hypothesis Based Hunting
IOC Hunting
Indicator of Compromise
IOA Hunting
Indicator of Attack
Behavioral Hunting
Anomaly Hunting
Statistical Hunting
Baseline Comparison
MITRE ATT&CK Mapping
MITRE ATT&CK
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Supporting Enterprise Tools
Zeek
Network metadata
Suricata
IDS IPS
Snort
Signature IDS
Arkime
Full packet indexing
Wireshark
Packet analysis
tcpdump
Packet capture
NetworkMiner
Network forensic analysis
Security Onion
Complete NSM platform
Elastic Stack
SIEM
Splunk
SIEM
Wazuh
SIEM HIDS XDR
Malcolm
Network traffic analysis
Arkime
Packet indexing
Moloch
Old name of Arkime
Enterprise Linux Commands
Network
ip addr
ip route
ss -tulnp
netstat -ant
DNS
dig
host
nslookup
Packet Capture
tcpdump
Processes
ps aux
top
htop
Logs
journalctl
tail
less
grep
File Search
find
locate
Permissions
chmod
chown
getfacl
setfacl
Important Linux Paths
Zeek
/opt/zeek/
/opt/zeek/logs/current/
/opt/zeek/share/
/opt/zeek/bin/
Logs
/var/log/
/var/log/syslog
/var/log/auth.log
/var/log/messages
MongoDB
/var/lib/mongodb/
Configuration
/etc/
Temporary
/tmp/
/var/tmp/
Investigation Process
Alert Received
Verify Evidence
Validate Logs
Timeline Analysis
Network Analysis
Host Analysis
Malware Analysis
IOC Extraction
Threat Intelligence Lookup
Scope Investigation
Containment
Eradication
Recovery
Lessons Learned
Threat Intelligence
IOC
IP Address
Domain
URL
Hash
Reputation
VirusTotal
AbuseIPDB
AlienVault OTX
MISP
Enrichment
ASN
Country
WHOIS
Passive DNS
SOC Workflow
Tier 1 Analyst
Alert triage
Tier 2 Analyst
Investigation
Tier 3 Analyst
Threat hunting
Incident Responder
Containment
DFIR Team
Deep forensic analysis
Enterprise Best Practices
Collect Zeek logs continuously
Synchronize time using NTP
Store logs centrally
Protect log integrity
Retain logs for long periods
Encrypt log storage
Use RBAC
Role Based Access Control
Monitor sensor health
Backup databases
Integrate with SIEM
Map detections to MITRE ATT&CK
Document investigations
Automate reporting
Validate detections regularly
Skills Required
Linux Administration
Networking
TCP
UDP
DNS
HTTP
HTTPS
TLS
SSH
Python
Bash
Regular Expressions
Wireshark
Zeek
RITA
MITRE ATT&CK
Threat Intelligence
Digital Forensics
Incident Response
SIEM
Malware Analysis
Log Analysis
Scripting