Kestrel

September 14, 2023

Announcing the Team Threat Hunting Project

Kestrel as a Service The Open Cybersecurity Alliance (OCA) is excited to announce the next milestone of the Kestrel subproject, Kestrel as a Service (KaaS).  KaaS enables threat hunting at scale to improve threat detection.   It is a Kestrel container and a deployable cloud-managed hunting service for large organizations. The project provides the code and instructions for deploying a […]
August 8, 2023

OCA and Kestrel at Black Hat 2023

At the Black Hat 2023 conference, attendees will hear from security experts sharing groundbreaking research at the Briefings, view demos of open-source tools at Arsenal, meet sponsors presenting a range of products and solutions in the Business Hall, and network with thousands of security professionals. Don’t miss out on the Kestrel session on Wednesday, 9 August, 1:00 PM – 2:30 […]
July 11, 2023

Kestrel Data Retrieval Explained

Kestrel provides a layer of abstraction to compose hunt-flows with standard hunt steps that run across many data sources and data types. This blogs overviews how data is retrieved, processed, and stored in Kestrel, and explains the 10x data retrieval performance improvement through Kestrel 1.5, 1.6, and 1.7.
June 15, 2023

End-to-end Testing for Cyber-Security Applications

Announcing the Federated Search End-To-End Testing GitHub Repository and its first CI/CD usage for Kestrel, a federated search application. Read on.
April 28, 2023

Detecting Malicious Remote Authentication Requests Using Graph Learning

This article introduces a new Kestrel analytics which detects lateral movement using graph learning.
February 27, 2023

A Kestrel Analytics to Detect Lateral Movement

Given the dramatic rise in number of cybersecurity attacks in the recent years, threat hunting is very important to secure businesses and enterprises. This post discusses a new approach to detect lateral movement and shows how this approach can be applied on the data read using STIX-Shifter in the Kestrel threat hunting platform.
October 31, 2022

Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator

Ready-made datasets from the Open Threat Research Forge meet Kestrel, featuring PowerShell Empire!
July 27, 2022

Try Kestrel in a Cloud Sandbox

Introducing the Kestrel cloud sandbox. Now learning and trying Kestrel is just a click away—no installation needed, no server needed.