itsMe Posted October 21, 2022 Share Posted October 21, 2022 This is the hidden content, please Sign In or Sign Up RedEye is an open-source analytic tool developed by CISA and DOE’s Pacific Northwest National Laboratory to assist Red Teams with visualizing and reporting command and control activities. This tool, released in October 2022 on GitHub, allows an operator to assess and display complex data, evaluate mitigation strategies, and enable effective decision making in response to a Red Team assessment. The tool parses logs, such as those from Cobalt Strike, and presents the data in an easily digestible format. The users can then tag and add comments to activities displayed within the tool. The operators can use the RedEye’s presentation mode to present findings and workflow to stakeholders. RedEye can assist an operator to efficiently: Replay and demonstrate Red Team’s assessment activities as they occurred rather than manually pouring through thousands of lines of log text. Display and evaluate complex assessment data to enable effective decision making. Gain a clearer understanding of the attack path taken and the hosts compromised during a Red Team assessment or penetration test. This is the hidden content, please Sign In or Sign Up Link to comment Share on other sites More sharing options...
Recommended Posts