LevelBlue SpiderLabs has released RAVEN, an open-source offensive security framework with 19 modules targeting Elasticsearch and Kibana environments. The tool automates reconnaissance, credential brute-forcing, exploitation of 8 tracked CVEs (three in CISA's KEV catalog, CVSS up to 10.0), Kibana-specific attacks, data exfiltration, and persistence via rogue users and long-lived API keys. Defenders should treat the release of this tool as an indicator that adversaries now have a consolidated, purpose-built toolkit for attacking exposed Elasticsearch/Kibana infrastructure.
Offensive Tooling
1 post
Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes