Sign inSign up

cernity/behavioral-detectors

By cernity

Updated 10 days ago

RITA-style behavioral detection (beaconing, exfil, DNS tunneling) over Suricata flow telemetry

Image
0

974

cernity/behavioral-detectors repository overview

Cernity — behavioral-detectors

RITA-style behavioral detection (beaconing, exfil, DNS tunneling) over Suricata flow telemetry.

Part of Cernity — central network detection & response (NDR) analytics for Suricata sensors. Suricata inspects packets at the edge and ships telemetry; Cernity runs the heavy, stateful, Zeek/RITA-style analysis centrally and emits security findings to your SIEM.

Raw network telemetry is analytics input. Security findings are SIEM input.

This image

cernity/behavioral-detectors — RITA-style behavioral detection (beaconing, exfil, DNS tunneling) over Suricata flow telemetry.

Quickstart

See a finding end to end with no live sensor:

docker compose -f deploy/quickstart/docker-compose.yml up
Deploy
  • Single host — Docker Compose (evaluation / small sites)
  • Manual multi-server — Compose across your own hardware, no orchestration
  • Kubernetes — Helm chart with autoscaled detectors

Scales to ~1,000 sensors / ~10 Gbps of edge inspection. Full docs, architecture, and sizing guide: https://github.com/cernity/cernityndr

License

Source-available under the PolyForm Perimeter License 1.0.1 — use it any way you like, except providing it to others as a competing product. "Cernity" is a trademark of the Cernity Project.

Tag summary

Content type

Image

Digest

sha256:68a8d2a69

Size

123.1 MB

Last updated

10 days ago

docker pull cernity/behavioral-detectors