Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

RITA

Real Intelligence Threat Analytics: ingest Zeek logs to score beaconing, long connections, blacklisted DNS, and lateral patterns.

Why it is included

Standard open companion to Zeek for finding C2-style network behavior without signature-only IDS.

Best for

Hunters and IR teams already exporting Zeek conn/DNS/http datasets.

Strengths

  • Beaconing analytics
  • Zeek-native
  • CLI + UI options

Limitations

  • Quality follows Zeek coverage and log fidelity

Good alternatives

Elastic ML jobs · commercial NDR analytics

Related tools