# activecm/rita-legacy

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Repository: https://github.com/activecm/rita-legacy
Canonical: https://ross.abutalabs.com/products/rita-legacy
Language: Go
License: GPL-3.0
License Family: copyleft
Topics: rita, network-traffic, threat, scanning, offensive-countermeasures, bro-ids, blueteam, security, logs, analytics, analysis, bhis, beacon, beacon-sniffer, dns, dns-tunneling, dga
Last push: 2026-01-12T23:00:09+00:00

## Health v2 (maintenance only)
Score: 59/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 62, release rhythm 33, longevity 100
- inputs: {"age_days": 3630, "days_push": 233, "days_rel": 233, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2509, forks 352 (observed 2026-08-28T04:06:57.332830+00:00)

## What it is
RITA (Real Intelligence Threat Analytics) is an open-source framework for detecting command and control communication through network traffic analysis. It ingests Zeek logs in TSV format and provides beaconing detection, DNS tunneling detection, and blacklist checking. This legacy repository is archived and unmaintained; the project has been rewritten at activecm/rita.

## Use cases
- detect command and control beaconing in network traffic
- find DNS tunneling covert channels
- analyze Zeek logs for suspicious domains
- check hosts against threat blacklists
- hunt for malware beacon behavior on my network
- blue team network threat analytics

## When to choose
- you need the original RITA feature set and cannot migrate
- you run an older environment (Ubuntu 20.04, CentOS 7, Security Onion) supported by its install script

## When to avoid
- starting a new deployment - use the rewritten activecm/rita instead
- you need maintained software with ongoing support
- you need features beyond beaconing, DNS tunneling, and blacklist checks

## Facets
- artifact type: framework
- maturity: abandoned
- function: analytics, monitoring, security, search-engine
- domain: security, networking, analytics, developer-tools
- platform: go, cli
- tags: network-traffic-analysis, zeek-logs, beaconing-detection, dns-tunneling, threat-hunting, blue-team, mongodb, legacy-archived, linux, docker

## Member repositories
- activecm/rita-legacy (main) score 59

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:57.332830+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:26:27.227507+00:00, confidence not recorded.
  - readme: https://github.com/activecm/rita-legacy (fetched 2026-08-28T04:06:57.332830+00:00, sha f2deadc539a0)
- Data as of 2026-08-30T08:39:29.467469+00:00.
