Skip to content

Bluekeep detection rule by using Apache Flink CEP (Complex Event Processing) Library and Markov Chain.

Notifications You must be signed in to change notification settings

NybbleHub/Bluekeep-Detection-Rule

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Flink CEP : Bluekeep Detection Rule

This demo show how to use Apache Flink CEP library and Markov Chain to create a Bluekeep Scan and Exploit detection rule and generate an alert that will be sent to Elasticsearch.

Documentation

Bluekeep Detection Rule is fully documented here: Bluekeep Detection Rule GitBook documentation

Documentation provides details about installation and configuration of each components of the demo, information about the dataflow and the code itself.

Pattern Sequence

Bluekeep rule Apache Flink CEP Pattern Sequence

About

Bluekeep detection rule by using Apache Flink CEP (Complex Event Processing) Library and Markov Chain.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages