Hello, I am a 16-year-old security researcher from Baku, Azerbaijan.
I built a Python tool called RedSEC that parses output from red team tools (nmap, nuclei, ffuf, hydra, impacket, metasploit and others), correlates events into attack chains, and exports the results as SEC .conf files. After reading Risto Vaarandi's 2002 IEEE paper, I emailed him directly. He responded and suggested I post here, and mentioned the more complex rule types — contexts and synthetic events. Following his advice, I implemented PairWithWindow, Context, and Synthetic rule support in v1.1.0. The exported rules use type=Single, type=SingleWithThreshold, and type=PairWithWindow depending on the correlation type detected. GitHub: https://github.com/alisalive/RedSEC I would welcome any feedback from the SEC community. Best regards, Shikhali Jamalzade
_______________________________________________ Simple-evcorr-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/simple-evcorr-users
