logo

Introduction to Zeek Log Analysis

ID: e82be8dd-f40e-59f7-a112-ae20373ab68e

STIX ID: report--e82be8dd-f40e-59f7-a112-ae20373ab68e

Feed Name: Black Hills Infosec Blog

Date Published: 2025-01-13

Date Updated: 2026-04-27

Author: BHIS

...
...

This transcript of a December 19, 2024 BHIS webcast features Troy Wojewoda giving an introductory deep-dive into Zeek (formerly Bro). It explains deployment options (passive tap/span and PCAP replay), compares log output formats (tab-separated vs JSON), catalogs common Zeek logs (conn, http, ssl, dns, files, pe, quic/HTTP3, etc.), and details key fields and identifiers (ts, uid, fuid, originator/responder, durations, flags). The talk also covers parsing and tooling (zeek-cut, jq), extension packages (ja3, community id), practical detection and notice strategies, auditing uses (cipher/SSH/SMB versions, cleartext protocols), and operational considerations for SOCs and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.