# Kunai: From Zero to Ninja — Quentin JEROME

**URL:** <https://discourse.ossbase.org/t/kunai-from-zero-to-ninja-quentin-jerome/696>\
**Category:** 2025 talks / workshops\
**Tags:** 2025, training, hacklu\
**Created:** [August 26, 2025, 8:56am UTC](https://discourse.ossbase.org/t/kunai-from-zero-to-ninja-quentin-jerome/696 "2025-08-26T08:56:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![system](https://discourse.ossbase.org/uploads/default/original/1X/4713f3d4fec85f7513775fc2dd36f548a49f8faa.jpeg) [@system](https://discourse.ossbase.org/u/system)\
**Post date:** [August 26, 2025, 8:56am UTC](https://discourse.ossbase.org/t/kunai-from-zero-to-ninja-quentin-jerome/696/1 "2025-08-26T08:56:24Z")

</div>

**Join us at hack.lu 2025 — [Info & Registration](https://2025.hack.lu/info/)**

**Duration:** 120 min  
  
**Type:** Training  
  
**Speakers:** Quentin JEROME

**Abstract**

In this workshop, participants will learn everything they need to know to install Kunai and start monitoring their Linux environment to spot attackers or simply for fun.

In the first part, we will cover all the essential information about Kunai. This will include a quick walkthrough of the Kunai documentation, explaining what participants can expect from this tool. Simultaneously, we will conduct exercises to help participants become familiar with the tool, its command line, and configuration file.

In the second part, we will run exercises showcasing more advanced Kunai usage. This will include building custom detection rules to detect specific anomalies or malware, learning how to load Indicators of Compromise (IoCs) into the detection engine, and how to integrate Kunai with your favorite MISP instance. If time allows, we will also cover additional advanced topics.

**Description**

In this workshop, participants will learn everything they need to know to install Kunai and start monitoring their Linux environment to spot attackers or simply for fun.

### Part 1: Introduction to Kunai

- **Essential Information** : Cover all the essential information about Kunai.
- **Documentation Walkthrough** : Quick walkthrough of the Kunai documentation, explaining what participants can expect from this tool.
- **Hands-on Exercises** : Conduct exercises to help participants become familiar with the tool, its command line, and configuration file.

### Part 2: Advanced Kunai Usage

- **Custom Detection Rules** : Building custom detection rules to detect specific anomalies or malware.
- **Indicators of Compromise (IoCs)**: Learning how to load IoCs into the detection engine.
- **Integration with MISP** : How to integrate Kunai with your favorite MISP instance.
- **Additional Topics** : If time allows, we will also cover additional advanced topics.

[View on pretalx](https://pretalx.com/hack-lu-2025/talk/XGVKFA/)

---

<div class="post-metadata">

**Author:** ![qjerome](https://discourse.ossbase.org/user_avatar/discourse.ossbase.org/qjerome/32/48_2.png) [@qjerome](https://discourse.ossbase.org/u/qjerome)\
**Post date:** [October 21, 2025, 9:28am UTC](https://discourse.ossbase.org/t/kunai-from-zero-to-ninja-quentin-jerome/696/2 "2025-10-21T09:28:45Z")

</div>

Hi everyone,

For anyone wanting to join this training, please make sure to complete the requirements: [workshops/circl-vss-2025 at main · kunai-project/workshops · GitHub](https://github.com/kunai-project/workshops/tree/main/circl-vss-2025)

Basically, you will need a machine where you can run Kunai. We provide a x86\_64 based VM, you can download at: [https://cra.circl.lu/circl-vss-2025/circl-vss-vm.ova](https://cra.circl.lu/circl-vss-2025/circl-vss-vm.ova)

If you are running an ARM based computer or if you prefer to use your own VM, feel free to come with it ready for the training.
