# cisagov/RedEye

RedEye is a visual analytic tool supporting Red & Blue Team operations

Repository: https://github.com/cisagov/RedEye
Canonical: https://ross.abutalabs.com/products/redeye
Homepage: https://cisagov.github.io/RedEye/
Language: TypeScript
License: BSD-3-Clause
License Family: permissive
Topics: blue-team, cybersecurity, red-team
Archived: true
Last push: 2023-10-20T10:45:05+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1430, "days_push": 1048, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2767, forks 291 (observed 2026-08-28T04:07:18.722331+00:00)

## What it is
RedEye is an open-source visual analytic tool from CISA and PNNL for visualizing and reporting Red Team command-and-control activities. It parses C2 logs such as Cobalt Strike logs and presents them in an interactive web UI with tagging, comments, and presentation mode.

## Use cases
- visualize cobalt strike c2 logs from a red team engagement
- replay and demonstrate red team assessment activities to stakeholders
- analyze attack paths and compromised hosts from a penetration test
- review red team campaign exports in a read-only blue team mode
- tag and annotate command and control activity for reporting
- present red team findings without manually reading thousands of log lines

## When to choose
- you need to visualize and report on Cobalt Strike or similar C2 logs after a red team assessment
- you want a dedicated tool to replay attack timelines for blue team or stakeholder briefings
- you need to analyze attack paths and compromised hosts from penetration test logs

## When to avoid
- you need actively developed software with new features, since the repo is in maintenance mode
- you need a general-purpose SIEM or log aggregation platform rather than C2 log analysis
- your C2 framework logs are not supported by RedEye's parsers

## Facets
- artifact type: application
- maturity: maintenance
- function: data-visualization, parser, security
- domain: security, penetration-testing
- platform: cross-platform, cli
- tags: red-team, blue-team, c2-logs, cobalt-strike, penetration-testing, log-analysis, cybersecurity, visualization, web-server

## Member repositories
- cisagov/RedEye (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:18.722331+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T08:16:44.112054+00:00, confidence not recorded.
  - readme: https://github.com/cisagov/RedEye (fetched 2026-08-28T04:07:18.722331+00:00, sha 3725551da4cf)
  - homepage: https://cisagov.github.io/RedEye/ (fetched 2026-08-29T09:56:25.431444+00:00, sha efaff5b6dedd)
- Data as of 2026-08-30T08:39:29.467469+00:00.
