Detecting Malware Beacons With Zeek and RITA
ID: 991772c6-d678-50a3-982d-4dbc2c103dd4
STIX ID: report--991772c6-d678-50a3-982d-4dbc2c103dd4
Feed Name: Black Hills Infosec Blog
This document is a tutorial on using RITA within the ADHD distribution to detect beaconing behavior in network traffic analyzed from Zeek (Bro) logs, contrasting RITA’s analytics engine with the AI Hunter commercial GUI. It demonstrates interpreting RITA’s HTML output on a lab PCAP (e.g., many consistent-interval connections from 10.234.234.100 to a DigitalOcean IP) and explains beacon indicators such as interval regularity, consistent data sizes, and jitter/dispersion, emphasizing that high-scoring beacons warrant investigation and can be filtered via whitelists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
