Sign inSign up

bl4ckj4ck/rocket

By bl4ckj4ck

•Updated 3 months ago

Parse, filter, correlate, and enrich logs from any source. Single static binary

Image
Security
0

426

bl4ckj4ck/rocket repository overview

⁠Rocket

Blue Team Log Analysis Toolkit — Convert any log format to structured CSV or JSON in seconds.

⁠Quick Start

# Parse logs
docker run -v ./logs:/logs bl4ckj4ck/rocket parse /logs/ -r -o /output/

# Quick triage
docker run -v ./logs:/logs bl4ckj4ck/rocket stats /logs/firewall.log --fields srcip,attack --top 10

# Extract IOCs
docker run -v ./logs:/logs bl4ckj4ck/rocket ioc /logs/firewall.log --types ipv4 --top 20

# GeoIP (mount geodb)
docker run -v ./logs:/logs -v ./geodb:/geodb bl4ckj4ck/rocket geoip /logs/firewall.log --db /geodb/ --top 10

# Sigma rules
docker run -v ./logs:/logs -v ./rules:/rules bl4ckj4ck/rocket sigma /logs/Security.evtx --rules /rules/

# Timeline
docker run -v ./logs:/logs bl4ckj4ck/rocket timeline /logs/syslog /logs/firewall.log -o /logs/timeline.csv

Supported Formats

keyvalue, json, syslog, cef, leef, apache, w3c, nginx-error, bind9, android, evtx (Windows Event Log)

Features

- 11 log format parsers with auto-detection
- CSV and JSON output
- IOC extraction (IPv4, IPv6, domains, URLs, emails, MD5, SHA1, SHA256)
- Sigma detection rules engine
- GeoIP resolution (MaxMind GeoLite2)
- Timeline builder for multi-source correlation
- Advanced filtering (text, regex, date-range, dedup)
- Streaming I/O — handles multi-GB files
- 1.95 MB image, zero dependencies

Links

- Website: https://rocket.sockets.ar
- GitHub: https://github.com/hernannh/rocket
- Documentation: https://github.com/hernannh/rocket/blob/main/README.md
- License: Apache 2.0

Tag summary

Content type

Image

Digest

sha256:1d620dd3c…

Size

2.1 MB

Last updated

3 months ago

docker pull bl4ckj4ck/rocket