Validated Architecture Design Review assessment automation tool
5.2K
EleVADR is a specialized network security analysis engine developed for the Cybersecurity and Infrastructure Security Agency (CISA). It is designed to assess Operational Technology (OT) systems by transforming raw PCAP traffic into actionable security intelligence.
This is part of the larger EleVADR operator workflow.
eleVADR analyzes OT network traffic to provide comprehensive security assessments including:
To ensure environment parity and avoid "it works on my machine" issues, EleVADR must be run and developed inside containers.
Do not attempt to install dependencies locally. Use containerization tools.
A pre-built container for the latest develop image is available on
DockerHub.
sudo docker run -i cisagov/elevadr-web-backend
# Build the analysis engine
docker build -t elevadr-analysis .
# Run analysis on a PCAP
docker run --rm \
-v $(pwd)/pcaps:/input:ro \
-v $(pwd)/reports:/output \
elevadr-analysis
We use VS Code Dev Containers to provide a fully configured environment, including Zeek, Python 3.14, and all required system dependencies.
How to start developing:
Ctrl+Shift+P and choose
Dev Containers: Rebuild and Reopen in Container.Why Dev Containers?
pyenv, zeek, or libpcap on your host.EleVADR is a data pipeline that transforms raw network traffic into security intelligence:
PCAP → Zeek (Log Generation) → Pandas
(Data Enrichment) → JSON Report
uvOnce inside the Dev Container, run tests with pytest:
pytest
All tests live in tests/.
Developed for the Cybersecurity and Infrastructure Security Agency (CISA).
Content type
Image
Digest
sha256:82449b61a…
Size
424.5 MB
Last updated
4 months ago
docker pull cisagov/elevadr-web-backend:sha-28d8d48