activecm / rita-legacy

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
GNU General Public License v3.0
2.51k stars 362 forks source link

Current default column names for show-beacons #826

Open roboticsea opened 6 months ago

roboticsea commented 6 months ago

Hey there, hopefully just a quick question. I'm helping some folks interpret their RITA data so wrapping my head around the dataset.

What are the default list of columns for show-beacons? I've reviewed all the code and a lot of documentation and I keep seeing references to the "intvl skew" but I'm not seeing that column any longer, only the scores.

Is this right?

Thanks!

Rob C