Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes
ID: b51e6a44-3b75-5c24-931b-3a8cf059c457
STIX ID: report--b51e6a44-3b75-5c24-931b-3a8cf059c457
Feed Name: LevelBlue SpiderLabs Blog
RAVEN is an open-source, modular offensive security framework purpose-built to test Elasticsearch and Kibana deployments from discovery through exploitation and cleanup: it provides 19 modules covering reconnaissance, credential attacks, CVE detection and exploitation (including multiple RCEs and Kibana-specific flaws), exfiltration and persistence, and nine Docker lab environments for safe testing; the post introduces RAVEN’s capabilities, tracked CVEs (some with full exploit implementations), safety guardrails, and a five-part series that walks through an entire offensive engagement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
