# outflanknl/RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Repository: https://github.com/outflanknl/RedELK
Canonical: https://ross.abutalabs.com/products/redelk
Language: Python
License: BSD-3-Clause
License Family: permissive
Topics: security, siem, monitoring, elastic, elasticsearch, logstash, kibana, red-teaming
Last push: 2026-04-28T18:08:10+00:00

## Health v2 (maintenance only)
Score: 58/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 79, release rhythm 8, longevity 100
- inputs: {"age_days": 2891, "days_push": 127, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2665, forks 392 (observed 2026-08-28T04:07:09.004695+00:00)

## What it is
RedELK is a self-hosted SIEM built on the Elastic stack (Elasticsearch, Logstash, Kibana) tailored for red team operations. It aggregates and enriches operational logs from teamservers and traffic logs from redirectors, providing operational oversight and alerts when the Blue Team investigates red team infrastructure.

## Use cases
- track red team operator activity across multiple teamservers in one place
- detect when the blue team is investigating my C2 infrastructure
- give the white team a read-only view of a long-running red team operation
- search historical logs, screenshots, IOCs and keystrokes from a months-long engagement
- centralize traffic logs from multiple redirectors and get alerted on defensive activity
- manage oversight for multi-scenario, multi-member red team campaigns

## When to choose
- you run long-term, multi-teamserver red team operations needing centralized logging
- you want to alarm on blue team activity against your redirector infrastructure
- you already use or are comfortable with the Elastic stack and Docker deployments

## When to avoid
- you need a general-purpose enterprise SIEM for blue team defense rather than red team operations
- you want a lightweight single-binary tool without Elasticsearch infrastructure overhead
- your engagement is short and simple enough that centralized log aggregation adds no value

## Facets
- artifact type: application
- maturity: active
- function: monitoring, alerting, logging, search-engine, security, data-visualization
- domain: security, monitoring, self-hosted, developer-tools
- platform: self-hosted
- tags: red-team, siem, elk-stack, blue-team-detection, penetration-testing, c2-logging, elastic-stack, docker, linux, web-server

## Member repositories
- outflanknl/RedELK (main) score 58

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:09.004695+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:18:17.709227+00:00, confidence not recorded.
  - readme: https://github.com/outflanknl/RedELK (fetched 2026-08-28T04:07:09.004695+00:00, sha 6996be1ad3bf)
- Data as of 2026-08-30T08:39:29.467469+00:00.
