activecm / rita

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
https://www.activecountermeasures.com/free-tools/rita/
GNU General Public License v3.0
189 stars 22 forks source link

Feature: Show IP and Hostname #15

Open joswr1ght opened 3 months ago

joswr1ght commented 3 months ago

In the detail view for the selected entry, if a hostname is displayed there is no opportunity to see the IP address of the selected destination. The analyst must refer to Zeek logs or perform DNS name resolution to identify the IP address of the threat, both of which are not ideal. Screenshot attached.

Feature request: Display the IP address even when a DNS name is extracted about a host, either SRC or DST.

Screenshot 2024-08-05 at 6 53 40 AM