Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Extracts fields from zeek logs, compatible with zeek-cut
Device profile: Define acceptable amounts of traffic for your devices and see a report of outliers.
Collect IPFIX / Netflow v9 Records and Ship them to RITA for Analysis