Awesome AI for Infra › Anomaly Detection

activecm/rita

⭐ 651 Go added to this list on 2026-06-14 repository created 2024-06-27

RITA (Real Intelligence Threat Analytics) is a robust open-source framework designed for the specialized task of detecting sophisticated command and control (C2) communication within network traffic. By ingesting Zeek logs in TSV or JSON format, RITA applies several analytical capabilities to uncover malicious activity. Key features include active beaconing detection, which identifies regular, rhythmic communication patterns often indicative of C2 channels; long connection detection, pinpointing unusually extended network sessions; and DNS tunneling detection, which uncovers covert communication methods exploiting DNS queries. Furthermore, RITA integrates with threat intelligence feeds to cross-reference suspicious domains and hosts, enhancing its ability to identify known malicious entities. The framework is deployed via Docker and offers a command-line interface for importing data, configuring settings, and searching for threats with a GitHub-style syntax. While not explicitly using 'AI' or 'ML' terminology in its description, its core function of detecting subtle, often complex, network anomalies and patterns for C2 communication aligns with an AI-for-Ops approach, particularly in the realm of threat intelligence and behavioral analysis for SecOps, as it automates the detection of patterns that human analysts would struggle to find at scale.

https://github.com/activecm/rita

anomaly-detectionbeaconsblue-teamc2c2-detectioncommand-and-controlcyber-securityincident-responseintrusion-detectionlog-analysisnetwork-monitoringnetwork-traffic-analysissecurity-toolsthreat-huntingthreat-intelligencezeeksecops

Also in Anomaly Detection

yzhao062/pyod

PyOD is a comprehensive Python library for multi-modal anomaly detection, offering 60+ detectors and an agentic workflow for AI agents to drive investigations across various data types.

datamllab/tods

TODS is a comprehensive automated machine learning system for multivariate time-series outlier detection, providing modules for preprocessing, feature extraction, and a wide array of detection algo...

sintel-dev/Orion

Orion is an open-source machine learning library from MIT's Data to AI Lab, focused on unsupervised time series anomaly detection using various AI-driven pipelines.

khundman/telemanom

Telemanom is a framework using LSTMs and automatic thresholding for unsupervised anomaly detection in multivariate time series data, originally developed for spacecraft telemetry.

MentatInnovations/datastream.io

datastream.io is an open-source framework for real-time anomaly detection in streaming data using Python, Elasticsearch, and Kibana.

zillow/luminaire

Luminaire is a Python package from Zillow that provides ML-driven solutions for monitoring time series data through automated anomaly detection and forecasting.

Stream-AD/MIDAS

MIDAS is a C++ implementation for real-time anomaly detection in dynamic, time-evolving graphs, designed to identify intrusions, fraud, and fake rating anomalies with high accuracy and speed.

earthgecko/skyline

Skyline is a real-time anomaly detection and time series analysis system designed for passive monitoring of numerous high-resolution metrics without pre-configured models or thresholds.