{"adoption": {"forks": 392, "observed_at": "2026-08-28T04:07:09.004695+00:00", "stars": 2665}, "canonical_url": "https://ross.abutalabs.com/products/redelk", "card": {"archived": false, "artifact_type": "application", "description": "Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.", "domain": ["security", "monitoring", "self-hosted", "developer-tools"], "enriched": true, "function": ["monitoring", "alerting", "logging", "search-engine", "security", "data-visualization"], "health_score": 68, "homepage": null, "language": "Python", "license": "BSD-3-Clause", "license_family": "permissive", "maturity": "active", "member_repos": ["outflanknl/RedELK"], "name": "outflanknl/RedELK", "platform": ["self-hosted"], "pushed_at": "2026-04-28T18:08:10+00:00", "repo": "outflanknl/RedELK", "stars": 2665, "tags": ["red-team", "siem", "elk-stack", "blue-team-detection", "penetration-testing", "c2-logging", "elastic-stack", "docker", "linux", "web-server"], "topics": ["security", "siem", "monitoring", "elastic", "elasticsearch", "logstash", "kibana", "red-teaming"], "urls": [], "use_cases": ["track red team operator activity across multiple teamservers in one place", "detect when the blue team is investigating my C2 infrastructure", "give the white team a read-only view of a long-running red team operation", "search historical logs, screenshots, IOCs and keystrokes from a months-long engagement", "centralize traffic logs from multiple redirectors and get alerted on defensive activity", "manage oversight for multi-scenario, multi-member red team campaigns"], "what_it_is": "RedELK is a self-hosted SIEM built on the Elastic stack (Elasticsearch, Logstash, Kibana) tailored for red team operations. It aggregates and enriches operational logs from teamservers and traffic logs from redirectors, providing operational oversight and alerts when the Blue Team investigates red team infrastructure.", "when_to_avoid": ["you need a general-purpose enterprise SIEM for blue team defense rather than red team operations", "you want a lightweight single-binary tool without Elasticsearch infrastructure overhead", "your engagement is short and simple enough that centralized log aggregation adds no value"], "when_to_choose": ["you run long-term, multi-teamserver red team operations needing centralized logging", "you want to alarm on blue team activity against your redirector infrastructure", "you already use or are comfortable with the Elastic stack and Docker deployments"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/redelk", "repo": "outflanknl/RedELK", "role": "main", "score": 58}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:07:09.004695+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:18:17.709227+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6996be1ad3bf62d590e0057e4c490abca9b8214b555cfb77a76ab06bd76e1165", "fetched_at": "2026-08-28T04:07:09.004695+00:00", "kind": "readme", "missing": false, "url": "https://github.com/outflanknl/RedELK"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 79, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2891, "days_push": 127, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 58, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}