RITA
A network traffic analysis framework that detects command and control communication such as beaconing.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About RITA
RITA (Real Intelligence Threat Analytics) analyses network traffic data to find signs of command and control communication, the regular check-ins that compromised machines make to an attacker's server. It includes an importer, analysis modules and a viewer for the results, plus an installer and Docker files for deployment.
It suits threat hunters and defenders who already collect network logs and want to spot suspicious long-running or periodic connections. It is a Linux-oriented command-line tool rather than a point-and-click application.
Strengths
- Focused on detecting beaconing and command and control traffic
- Includes an importer, analysis and a results viewer
- Installer and Docker deployment files included
Limitations
- Requires existing network traffic logs to analyse
- Command-line setup aimed at security professionals
Details
- Pricing
- FreeFree to download from its public GitHub repository.
- License
- Open source, license not stated
- Developer
- Active Countermeasures
- Platforms
- Linux, Command line
- How it runs
- Downloadable app
- Best suited for
- Threat hunters looking for command and control traffic in network logs
- Categories
- Network tools, Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to RITA
Compare allSoftware that can replace RITA for an important use case, and what changes if you switch.
Security Onion
A free Linux distribution for network security monitoring, packet capture, detection and threat hunting.
Security Onion is a full Linux distribution for network security monitoring and threat hunting with packet capture and detection rules, installed from a single ISO.
Malcolm
A self-hosted network traffic analysis suite that turns PCAP files, Zeek logs and Suricata alerts into searchable dashboards.
Malcolm is a self-hosted multi-container suite turning PCAP files, Zeek logs and Suricata alerts into searchable dashboards, needing more server resources than RITA.
Similar software
Related functionality, not necessarily a direct replacement.
Zui
A desktop application for exploring data, and the official front end to Brim Data's SuperDB.
Arkime
Store and search captured network traffic through a web interface.
NetworkMiner
Network forensics tool that extracts files and credentials from captures.
Wireshark
The network protocol analyser: capture traffic and read it packet by packet, with dissectors for hundreds of protocols.
OpenCanary
A lightweight multi-protocol honeypot daemon that alerts when someone touches fake network services.
T-Pot
An all-in-one multi-honeypot platform with dashboards for analysing collected attack data.