-
Notifications
You must be signed in to change notification settings - Fork 393
Open
Labels
c2serversRelated to RedELK C2 server componentsRelated to RedELK C2 server componentsenhancementNew feature or requestNew feature or request
Description
Support for Mythic C2 - https://github.com/its-a-feature/Mythic
I just starting following the conversations to support Covenant C2 (#23) and immediately saw the same issues exist for Mythic (everything in a DB, no log files). I'd love to see Mythic support for RedELK, so can you all outline exactly what you'll need from Mythic to support log ingestion?
For Ghostwriter, we went the route of building Mythic Sync as a standalone tool that connects and listens for events to get the data where we want it, but isn't an ideal solution.
Is the list below (from Covenant Feature Request) the same items you'll need from Mythic/any other C2?
- Filebeat config to read the log file of Covenant on the c2 server
- Logstash rules that receive and filter the log lines
- Cron scripts running on the c2 server to copy relevant files (screenshots, downloaded files, etc) from the Covenant directory to the /home/scponly directory
- Modified rsync script on elkserver to copy files from /home/scponly on c2 server.
- Review of field names in rtops- index to check if they are relevant for c2 in general, or (still) are too Cobalt Strike dedicated.
- Update on documentation
CC @its_a_feature
dmaynor
Metadata
Metadata
Assignees
Labels
c2serversRelated to RedELK C2 server componentsRelated to RedELK C2 server componentsenhancementNew feature or requestNew feature or request