Alternatives to RITA
A network traffic analysis framework that detects command and control communication such as beaconing. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
RITA
A network traffic analysis framework that detects command and control communication such as beaconing.
Replacements
Listings that take over the same core job as RITA.
Security Onion
A free Linux distribution for network security monitoring, packet capture, detection and threat hunting.
Security Onion is a full Linux distribution for network security monitoring and threat hunting with packet capture and detection rules, installed from a single ISO.
Malcolm
A self-hosted network traffic analysis suite that turns PCAP files, Zeek logs and Suricata alerts into searchable dashboards.
Malcolm is a self-hosted multi-container suite turning PCAP files, Zeek logs and Suricata alerts into searchable dashboards, needing more server resources than RITA.
Similar software
Related functionality, not a direct replacement.
Zui
A desktop application for exploring data, and the official front end to Brim Data's SuperDB.
Arkime
Store and search captured network traffic through a web interface.
NetworkMiner
Network forensics tool that extracts files and credentials from captures.
Wireshark
The network protocol analyser: capture traffic and read it packet by packet, with dissectors for hundreds of protocols.
OpenCanary
A lightweight multi-protocol honeypot daemon that alerts when someone touches fake network services.
T-Pot
An all-in-one multi-honeypot platform with dashboards for analysing collected attack data.