Hello,

I am a 16-year-old security researcher from Baku, Azerbaijan.

I built a Python tool called RedSEC that parses output from red team
tools (nmap, nuclei, ffuf, hydra, impacket, metasploit and others),
correlates events into attack chains, and exports the results as SEC
.conf files.

After reading Risto Vaarandi's 2002 IEEE paper, I emailed him directly.
He responded and suggested I post here, and mentioned the more complex
rule types — contexts and synthetic events. Following his advice, I
implemented PairWithWindow, Context, and Synthetic rule support in v1.1.0.

The exported rules use type=Single, type=SingleWithThreshold, and
type=PairWithWindow depending on the correlation type detected.

GitHub: https://github.com/alisalive/RedSEC

I would welcome any feedback from the SEC community.

Best regards,
Shikhali Jamalzade
_______________________________________________
Simple-evcorr-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/simple-evcorr-users

Reply via email to