IBM contributed Kestrel, an open-source programming language for threat hunting, to the Open Cybersecurity Alliance (OCA) today in a move that Big Blue says marks a major milestone in OCA’s mission to drive greater interoperability across the security industry.
Kestrel, jointly developed by IBM Research and IBM Security, uses automation to accelerate threat hunting and allows security analysts to express hunts in an open, composable language. The machine-learning based automation and composable hunting flows reduce the time it takes to discover new threats and also to create new hunts, according to Jason Keirstead, CTO of threat management for IBM Security and co-chair of the OCA.
“Kestrel is designed to take advantage of the collective learned experience of the threat hunting community — and enable that to be combined with the power of machine learning and automation to speed response to threats,” he said in a statement. “By sharing new threat hunting patterns as they emerge via code that can be easily customized, Kestrel lets threat hunters devote more time to figuring out what to hunt, as opposed to how to hunt.”
IBM Security and McAfee spearheaded the open source group in 2019 and contributed the initial open source content and code. OCA aims to make the myriad security products on the market interoperable using open source code as well as open standards and protocols. It now has about 30 member organizations, and it’s governed under the auspices of OASIS Open.
Kestrel Joins OCA’s Open Source ProjectsAt launch, IBM Security contributed STIX-Shifter, and shortly after McAfee contributed the OpenDXL Standard Ontology, which is an open source language for connecting security tools. More than 4,100 vendors and enterprises now use this open messaging framework to develop and share integrations with other tools, according to McAfee.
Meanwhile, STIX Shifter is an open source library that can identify information about potential threats within a wide variety of data repositories and translate it into a format that can be analyzed by any security tool that has this standard enabled.
About a month after OCA formed, IBM announced the first commercial deployment of STIX Shifter in its containerized security platform Cloud Pak for Security. This product uses STIX Shifter to integrate with IBM and other vendors’ security tools as well as data from across a company’s infrastructure.
Additionally, Kestrel uses STIX Shifter’s federated data service capabilities. “It’s good to see additional capabilities being built upon STIX,” said Tyler Oliver, XDR product manager at EclecticIQ, in a statement. “The Kestrel project is a great example of how the community can develop normalized methods, in this case, a threat hunting language, to easily interact with the growing security technology landscape.”
Comments