Day 22 Detecting C2

Overview

RITA (Real Intelligence Threat Analytics)

Rita only read zeek log! So we need to convert pcap file to zeek first

3 steps:

  1. convert pcap to zeek
  2. have RITA read zeek log
  3. open RITA terminal