activecm / rita-legacy

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
GNU General Public License v3.0
2.5k stars 365 forks source link

Support Suricata as source #704

Open regit opened 2 years ago

regit commented 2 years ago

Given the data that you are using, is there a plan to support Suricata events as an alternative to Zeek ones ?

ethack commented 2 years ago

There isn't a plan currently, but this is a great suggestion so I'll leave the issue open.