logo

Detecting Malware Beacons With Zeek and RITA

ID: 991772c6-d678-50a3-982d-4dbc2c103dd4

STIX ID: report--991772c6-d678-50a3-982d-4dbc2c103dd4

Feed Name: Black Hills Infosec Blog

Date Published: 2020-03-03

Date Updated: 2026-04-27

Author: BHIS

...
...

This document is a tutorial on using RITA within the ADHD distribution to detect beaconing behavior in network traffic analyzed from Zeek (Bro) logs, contrasting RITA’s analytics engine with the AI Hunter commercial GUI. It demonstrates interpreting RITA’s HTML output on a lab PCAP (e.g., many consistent-interval connections from 10.234.234.100 to a DigitalOcean IP) and explains beacon indicators such as interval regularity, consistent data sizes, and jitter/dispersion, emphasizing that high-scoring beacons warrant investigation and can be filtered via whitelists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.