cisagov/RedEye

Parsers for additional C2 frameworks

GoldingAustin opened this issue ยท 7 comments

We're planning on integrating up to three additional C2 framework parsers this year into RedEye. The list of parsers is still being finalized, so please comment below with any framework parser you'd like to see in RedEye!

Would be happy to collaborate on implementing support for Sliver C2!

Mythic parsing would be amazing: https://github.com/its-a-feature/Mythic

when would a parser for sliver C2 available? Thanks.

Any update on parsers? Would love to see one for an open-source c2

Anyone here with some knowledge in Go can start on this I guess. @moloch-- already commented that he's open for collaboration. Just ping him and get started ๐Ÿ˜Š He's one of the main Sliver devs.

We will be merging the Brute Ratel parser soon!

For Sliver, we met with their team earlier this year and discussed additional data logging from Sliver that RedEye would need to parse a full campaign. The updated logging is in the recent Sliver v1.6 release, and we've started working on integrating a parser for RedEye based on that version! We don't have a solid date yet but we're targeting late August/early September for a beta release.