InfoSec_Notes

RITA - Real Intelligence Threat Analytics

Primary features

Notes

Usage

Convert Zeek logs for RITA

` $ zeek readpcap pcaps/asyncRAT.pcap zeek_logs/asyncRAT`

Import to RITA

` $ cd /zeek_logs/asyncRAT/ & ls $ rita import –logs /asyncRAT/ –database asyncrat`

View Results

` $ rita view asyncrat`

Things to look for?