/Bluekeep-Detection-Rule

Bluekeep detection rule by using Apache Flink CEP (Complex Event Processing) Library and Markov Chain.

Primary LanguageJava

Flink CEP : Bluekeep Detection Rule

This demo show how to use Apache Flink CEP library and Markov Chain to create a Bluekeep Scan and Exploit detection rule and generate an alert that will be sent to Elasticsearch.

Documentation

Bluekeep Detection Rule is fully documented here: Bluekeep Detection Rule GitBook documentation

Documentation provides details about installation and configuration of each components of the demo, information about the dataflow and the code itself.

Pattern Sequence

Bluekeep rule Apache Flink CEP Pattern Sequence