outflanknl/RedELK
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations. observed · 2026-08-28
Health v2 · maintenance only
58/100
- Activity 79
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2891
- days_rel: n/a
- days_push: 127
- n_releases_24m: 0
Adoption not part of the score
2665 stars · 392 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
RedELK is a self-hosted SIEM built on the Elastic stack (Elasticsearch, Logstash, Kibana) tailored for red team operations. It aggregates and enriches operational logs from teamservers and traffic logs from redirectors, providing operational oversight and alerts when the Blue Team investigates red team infrastructure.
Use cases
- track red team operator activity across multiple teamservers in one place
- detect when the blue team is investigating my C2 infrastructure
- give the white team a read-only view of a long-running red team operation
- search historical logs, screenshots, IOCs and keystrokes from a months-long engagement
- centralize traffic logs from multiple redirectors and get alerted on defensive activity
- manage oversight for multi-scenario, multi-member red team campaigns
When to choose
- you run long-term, multi-teamserver red team operations needing centralized logging
- you want to alarm on blue team activity against your redirector infrastructure
- you already use or are comfortable with the Elastic stack and Docker deployments
When to avoid
- you need a general-purpose enterprise SIEM for blue team defense rather than red team operations
- you want a lightweight single-binary tool without Elasticsearch infrastructure overhead
- your engagement is short and simple enough that centralized log aggregation adds no value
Facets
application · maturity active
monitoring alerting logging search-engine security data-visualization security monitoring self-hosted developer-tools self-hosted red-team siem elk-stack blue-team-detection penetration-testing c2-logging elastic-stack docker linux web-server
1 source
- readme: https://github.com/outflanknl/RedELK · fetched 2026-08-28 · 6996be1ad3bf
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| outflanknl/RedELK | main | 58 |
For agents
markdown · JSON · MCP: product_card(name="outflanknl/RedELK")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem