Skip to content

Latest commit

 

History

History
13 lines (7 loc) · 702 Bytes

README.md

File metadata and controls

13 lines (7 loc) · 702 Bytes

Flink CEP : Bluekeep Detection Rule

This demo show how to use Apache Flink CEP library and Markov Chain to create a Bluekeep Scan and Exploit detection rule and generate an alert that will be sent to Elasticsearch.

Documentation

Bluekeep Detection Rule is fully documented here: Bluekeep Detection Rule GitBook documentation

Documentation provides details about installation and configuration of each components of the demo, information about the dataflow and the code itself.

Pattern Sequence

Bluekeep rule Apache Flink CEP Pattern Sequence