Skip to content

Support for Mythic C2Β #63

@andrewchiles

Description

@andrewchiles

Support for Mythic C2 - https://github.com/its-a-feature/Mythic

I just starting following the conversations to support Covenant C2 (#23) and immediately saw the same issues exist for Mythic (everything in a DB, no log files). I'd love to see Mythic support for RedELK, so can you all outline exactly what you'll need from Mythic to support log ingestion?

For Ghostwriter, we went the route of building Mythic Sync as a standalone tool that connects and listens for events to get the data where we want it, but isn't an ideal solution.

Is the list below (from Covenant Feature Request) the same items you'll need from Mythic/any other C2?

  • Filebeat config to read the log file of Covenant on the c2 server
  • Logstash rules that receive and filter the log lines
  • Cron scripts running on the c2 server to copy relevant files (screenshots, downloaded files, etc) from the Covenant directory to the /home/scponly directory
  • Modified rsync script on elkserver to copy files from /home/scponly on c2 server.
  • Review of field names in rtops- index to check if they are relevant for c2 in general, or (still) are too Cobalt Strike dedicated.
  • Update on documentation

CC @its_a_feature

Metadata

Metadata

Assignees

No one assigned

    Labels

    c2serversRelated to RedELK C2 server componentsenhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions