CISA Offers Free RedEye Analytics Tool for Red Teams – DARKReading
The Cybersecurity and Infrastructure Security Agency (CISA) has rolled out a freeopen source tool to help red teams and penetration testers more efficiently conduct their analysis, visualization, and reporting activities. The platform could help harmonize the necessary, but often boring, work of communicating results to clients and management, the US Department of Homeland Security (DHS) agency said.
The tool, dubbed RedEye, helps visualize command-and-control activities, allowing the teams to replay assessment actions rather than manually parsing log files to recreate events. CISA, along with the Department of Energy's Pacific Northwest National Laboratory (PNNL), created the tool to meet its own internal needs but decided to publish the software to help other red teams and gather feedback and feature requests from the community as a whole.
"The open source release was centered around contributing to the global information security community," a CISA spokesperson told Dark Reading. "Diversity and openness of thought makes products better for everyone, and getting community feedback and even 'pull requests' to contribute to the project make for compelling on-ramps into improvements and helping the community at large."
A number of organizations have published significant security tools as open source software in the past year. In August, NetSPI released two adversary simulation tools, PowerHuntShares and PowerHunt, to help companies detect vulnerable network shares and manage their attack surfaces. In November 2021, Google published its ClusterFuzzLite software as open source, a program that allows application security specialists to run various fuzzing capabilities against their software. The company released two related tools, OSS-Fuzz and ClusterFuzz, in 2016 and 2019, respectively.
The RedEye project could be a boon to red teams, especially those at smaller companies and agencies that do not have the support of a development team to make internals tools, says Charles Henderson, global head of IBM Security's X-Force team. By making a red team's reporting and communicating tasks more efficient, the tool can open up more time to do as much red teaming as possible, he says. Daily tasks, such as data aggregation, collating data, and working on presentation all take a lot of time time that could be better spent simulating attacks.
"We spend a lot of time in security creating tools that are really centered around the 'cool' parts of security the stuff that gets presented at conferences," Henderson says. "The truth of the matter is that wespend a lot of time in security on auxiliary functions, like reporting and the aggregation of data, which are for lack of a better term unsexy. To the degree we can start to decrease the time sink associated with those tasks, then we are going to be far better at security."
RedEye can help red team members and executives understand the attack paths by creating visualizations of the entries in log files. The tool currently supports Cobalt Strike logs, but will expand to support telemetry from other red team toolsets, CISA said. The goal is to allow red team analysts to be able to better visualize and understand attempted and successful attack paths used during penetration tests and display that information clearly.
"This tool ... allows an operator to assess and display complex data, evaluate mitigation strategies, and enable effective decision making in response to a Red Team assessment," CISA said in the project documentation. "The tool parses logs, such as those from Cobalt Strike, and presents the data in an easily digestible format. The users can then tag and add comments to activities displayed within the tool."
The tool will be useful for companies that utilize in-house red teams as well as penetration-testing services as a way to standardize reporting. IBM creates its own tools to handle such activities, but the company is a "fairly advanced shop," says IBM Security's Henderson. "You would be surprised how few tools are out there for folks that may not not have the development resources that we do."
If RedEye becomes popular, it could help to standardize reporting formats and feature sets for reporting and analysis tools. However, CISA stresses that use of the tool is not a government requirement nor is it intended to be.
"While CISA is excited for the community to get the opportunity to use this tool on their own engagements, we trust that each red team will use the tools that meet their specific use case as they deem appropriate," the agency spokesperson said."RedEye can help augment the way in which offensive reports and evidence is presented to customers/clients, but it is not intended to drive universal alignment around a common standards."
Adversary-attack simulation tools such as Cobalt Strike and Brute Ratel have grown in popularity, not only with defenders, but with attackers as well. While many tools created to help red teams and penetration testers are dual use, equally beneficial to the attacker as well as the defender, but RedEye really does not fall into that category, IBM Security's Henderson says.
"Criminals have gotten much better at eliminating the time sinks in their operations and focusing on the return on their investments, and this is the first time in a long time that a tool is coming out that is focusing on efficiency gains for the defender," he says. "I think that benefit to the stakeholders in security testing is going to be far more meaningful than any benefit that could be provided to criminals."
The CISA spokesperson saidCISA plans to add a roadmap for the tool's development to the GitHub repository in the future, and specify which adversary-simulation tools it plans to support.
Go here to see the original:
CISA Offers Free RedEye Analytics Tool for Red Teams - DARKReading
- 10 open-source Windows apps I can't live without - and they're all free - ZDNET - October 15th, 2025 [October 15th, 2025]
- Borderlands 4: Gearbox Software Reveals Upcoming Content for the Game Including a DLC, a Free Event and More - IGN India - October 15th, 2025 [October 15th, 2025]
- Triple-zero software 'hanging by a thread' - Kyabram Free Press - October 15th, 2025 [October 15th, 2025]
- Free Up More Google Drive Space at No Cost With These Hacks - CNET - October 13th, 2025 [October 13th, 2025]
- 8 free Linux apps that make tricky tasks surprisingly easy - no command line required - ZDNET - October 13th, 2025 [October 13th, 2025]
- Running Out of Space on Your iPhone? Before You Delete Anything Try This - CNET - October 11th, 2025 [October 11th, 2025]
- 4 free video editors that make me question why I ever paid for Adobe software - XDA - October 9th, 2025 [October 9th, 2025]
- A 2TB PCIe 5.0 SSD for less than $140? This Crucial P510 Prime Big Deals Day discount with free Acronis software is exactly why I'm putting it... - October 9th, 2025 [October 9th, 2025]
- At 40 Years, Free Software Foundation Now Wants to 'Free Your Phone' - It's FOSS News - October 9th, 2025 [October 9th, 2025]
- 8 free Linux apps that are surprisingly useful - no command line required - ZDNET - October 4th, 2025 [October 4th, 2025]
- We Finally Have Free Anti-Robocall Tools That Work - The New York Times - October 4th, 2025 [October 4th, 2025]
- Illinois State Bar Association Offering Free Trust Accounting & Billing Software to All Members With Smokeball Bill - Illinois State Bar... - October 2nd, 2025 [October 2nd, 2025]
- Suffolk tech giant pledges $10m to give charities free software for life - Ipswich.co.uk - October 2nd, 2025 [October 2nd, 2025]
- Eventide Temperance Lite, "the world's first musical reverb plugin": free download for a limited time - synth anatomy - October 2nd, 2025 [October 2nd, 2025]
- Windows 10 extended support is now free, but only in Europe Microsoft capitulates on controversial $30 ESU price tag which remains firmly in place... - September 30th, 2025 [September 30th, 2025]
- You can now install iOS 26 on your iPhone: Everything to know about the free software update - Engadget - September 30th, 2025 [September 30th, 2025]
- Turns out, Microsoft will offer Windows 10 security updates for free until 2026but unfortunately not in the US or the UK - PC Gamer - September 30th, 2025 [September 30th, 2025]
- Free Alternatives to Photoshop and Word: How to Save on Software - 112.ua - September 30th, 2025 [September 30th, 2025]
- Delete those pricey programs with our four tips to help you find the best bargain software solutions - The Sun - September 30th, 2025 [September 30th, 2025]
- BlueCruise is Getting Better for Current Truck Owners - Ford From the Road - September 28th, 2025 [September 28th, 2025]
- Best typing tutor software of 2025 - TechRadar - September 25th, 2025 [September 25th, 2025]
- You can update your iPhone to iOS 26 for free right now - here's which models support it - ZDNET - September 25th, 2025 [September 25th, 2025]
- This is the best photo editing software to use in 2025 - Amateur Photographer - September 25th, 2025 [September 25th, 2025]
- From Abuse to Alignment: Why We Need Sustainable Open Source Infrastructure - Sonatype - September 25th, 2025 [September 25th, 2025]
- Think you've seen the weirdest place to play DOOM? Think again - Creative Bloq - September 23rd, 2025 [September 23rd, 2025]
- OpenSSF to freeloaders: Open source infra isn't free - theregister.com - September 23rd, 2025 [September 23rd, 2025]
- I transformed our LAN gaming setup with a mini PC and free software - XDA - September 21st, 2025 [September 21st, 2025]
- iOS 26 is ready to download: Everything to know about the free iPhone software update - Engadget - September 21st, 2025 [September 21st, 2025]
- Filmmakers - you can now storyboard your next movie totally free with this software - Yahoo! Tech - September 21st, 2025 [September 21st, 2025]
- Oak Creek Police Crime Analyst Wins Top International Award with Innovative Free Software Dashboard - Hoodline - September 21st, 2025 [September 21st, 2025]
- Molecularbytes Atomicreverbfree, a free algorithmic reverb for macOS and Windows - synth anatomy - September 19th, 2025 [September 19th, 2025]
- Meadows Introduces Free Imposition Software for Adobe InDesign - PRWeb - September 19th, 2025 [September 19th, 2025]
- Lucid just gave its EV owners a free dash cam mode and Tesla-style parking monitor all from a software update - TechRadar - September 19th, 2025 [September 19th, 2025]
- My Google Pixel just updated and is better than ever get your free software upgrade now - T3 - September 19th, 2025 [September 19th, 2025]
- NLSIU study hails Keralas KITE as key model for implementing Free and Open Source Software (FOSS) - The Times of India - September 19th, 2025 [September 19th, 2025]
- These are the top free Windows tools that I use on a daily basis to boost my productivity - Tom's Hardware - September 17th, 2025 [September 17th, 2025]
- iOS 26 is finally here: Everything to know about the free iPhone software update - Engadget - September 17th, 2025 [September 17th, 2025]
- When does iOS 26 come out? Date and time you can download the new iPhone operating system around the world - Fast Company - September 17th, 2025 [September 17th, 2025]
- Why Pie Is Becoming the UKs Go-To Free Tax Software in 2025 - The Globe and Mail - September 13th, 2025 [September 13th, 2025]
- iOS 26: What to know about the free iPhone software update ahead of the Apple event today - Engadget - September 11th, 2025 [September 11th, 2025]
- I built a photo editing workflow with nothing but free and open-source tools - xda-developers.com - September 9th, 2025 [September 9th, 2025]
- TapeFi Stop, free vinyl stop simulator plugin for macOS and Windows - synth anatomy - September 9th, 2025 [September 9th, 2025]
- Farming Simulator 25 Releases Third Free Update - Bleeding Cool News - September 6th, 2025 [September 6th, 2025]
- One of the biggest names in video editing is coming to smartphones and it's free. Meet Premiere Pro for mobile - Digital Camera World - September 5th, 2025 [September 5th, 2025]
- Microsoft wants to give US government Copilot for free - theregister.com - September 3rd, 2025 [September 3rd, 2025]
- I Thought My Gmail Inbox Was Toast. Then I Got Back 15GB of Free Storage - CNET - September 3rd, 2025 [September 3rd, 2025]
- The Truth About KMSPico Downloads: Risks and Better Alternatives - inkl - September 3rd, 2025 [September 3rd, 2025]
- Artistapirata Download Free Programs, Games, and Software in 2026 - nerdbot - August 29th, 2025 [August 29th, 2025]
- Cognyte Software Ltd. stock prediction for this week - July 2025 Closing Moves & Free Low Drawdown Momentum Trade Ideas - Newser - August 29th, 2025 [August 29th, 2025]
- Analyzing Upland Software Inc. with multi timeframe charts - Forecast Cut & Free Growth Oriented Trading Recommendations - Newser - August 29th, 2025 [August 29th, 2025]
- Can Upland Software Inc. recover in the next quarter - Options Play & Free Growth Oriented Trading Recommendations - Newser - August 27th, 2025 [August 27th, 2025]
- Custom watchlist performance reports with Asure Software Inc. - Weekly Market Summary & Reliable Breakout Stock Forecasts - Newser - August 27th, 2025 [August 27th, 2025]
- Is Paycom Software Inc. forming a reversal pattern - Trend Reversal & Free Reliable Trade Execution Plans - Newser - August 27th, 2025 [August 27th, 2025]
- What the charts say about CyberArk Software Ltd. today - Weekly Volume Report & Free Reliable Trade Execution Plans - Newser - August 26th, 2025 [August 26th, 2025]
- Is this a good reentry point in Guidewire Software Inc. - 2025 Market Sentiment & Free AI Powered Buy and Sell Recommendations - Newser - August 26th, 2025 [August 26th, 2025]
- Trend analysis for OneStream Software LLC this week - Weekly Trend Summary & Free Expert Approved Momentum Trade Ideas - Newser - August 24th, 2025 [August 24th, 2025]
- Detecting price anomalies in Paycom Software Inc. with AI - July 2025 Volume & Free Community Supported Trade Ideas - Newser - August 24th, 2025 [August 24th, 2025]
- Using AI based signals to follow Unity Software Inc. - July 2025 Breakouts & Free Verified High Yield Trade Plans - Newser - August 24th, 2025 [August 24th, 2025]
- Best graphic design software of 2025: Top picks tested for creative professionals and beginners - TechRadar - August 22nd, 2025 [August 22nd, 2025]
- Garmin Fenix 8 and Venu X1 get free software update that includes top features for runners and triathletes - Tom's Guide - August 22nd, 2025 [August 22nd, 2025]
- 6 Free and Open-Source Software for Creating Stunning Presentations - How-To Geek - August 18th, 2025 [August 18th, 2025]
- "It's one of the most powerful software sound design tools on earth and it's free": Try out this modular audio processing playground used... - August 18th, 2025 [August 18th, 2025]
- BetBlocker and ROGA Partner to Expand Free Gambling Blocker Access in the U.S. - European Gaming Industry News - August 14th, 2025 [August 14th, 2025]
- Hyundai & Kia thefts are down, Camaro ZL1 thefts are up, and a software glitch may be to blame. - wfmynews2.com - August 14th, 2025 [August 14th, 2025]
- There Is No Such Thing as Free Technology Software Solutions - ICTworks - August 12th, 2025 [August 12th, 2025]
- UnplugRed ModMan, a free perlin noise modulation plugin for mac, Linux and Windows - synth anatomy - August 12th, 2025 [August 12th, 2025]
- HY-Plugins HY-MBMFX3, multiband multi-FX plugin with modulation & free version - synth anatomy - August 7th, 2025 [August 7th, 2025]
- Choose the right software for Making Tax Digital for Income Tax - GOV.UK - August 3rd, 2025 [August 3rd, 2025]
- Best free PDF editor of 2025: We tested out these completely free to use apps - TechRadar - August 1st, 2025 [August 1st, 2025]
- D&D is 'here to earn your trust, not ask for it', starting with making Beyond's maps software free, brushing up the SRD, and sharing 'third-party... - August 1st, 2025 [August 1st, 2025]
- The Best Video Editing Software We've Tested (July 2025) - PCMag - July 27th, 2025 [July 27th, 2025]
- Download iOS 26 now and upgrade your iPhone to the Liquid Glass look for free - T3 - July 27th, 2025 [July 27th, 2025]
- What drives Smith Micro Software Inc. stock price - Free Smart Trading Workshop - Autocar Professional - July 24th, 2025 [July 24th, 2025]
- I've tested a bunch of PDF editors. These are the best - PCWorld - July 22nd, 2025 [July 22nd, 2025]
- V S Achuthanandan: From the freedom struggle to free software, to bringing MGR and Ilaiyaraaja he always thought of the people - The Indian Express - July 22nd, 2025 [July 22nd, 2025]
- Free, open-source software to reduce the mental workload of organic producers - Hortidaily - July 22nd, 2025 [July 22nd, 2025]
- Is OneStream Software LLC a good long term investment - Free Real-Time Stock Data - Autocar Professional - July 20th, 2025 [July 20th, 2025]
- How the Free Software Foundation Battles the LLM Bots - StartupNews.fyi - July 20th, 2025 [July 20th, 2025]
- How the Free Software Foundation Battles the LLM Bots - The New Stack - July 20th, 2025 [July 20th, 2025]
- Smith Micro Software Inc. Stock Analysis and Forecast - Free Risk Assessment Services - jammulinksnews.com - July 20th, 2025 [July 20th, 2025]