← All cheat sheets

ZEEK

Plain-text reference · 7 KB. Read it, search it (Ctrl-F) or print it.

Zeek (formerly Bro) is a network analysis framework.
Essential for network security monitoring and forensics.

INSTALLATION#

# Ubuntu/Debian
apt install zeek

# From source
git clone --recursive https://github.com/zeek/zeek
./configure && make && make install

BASIC USAGE#


            

LIVE CAPTURE#

zeek -i eth0                            # Monitor interface
zeek -i eth0 local.zeek                 # With script
zeek -i eth0 -C                         # Ignore checksums

PROCESS PCAP#

zeek -r capture.pcap                    # Read pcap
zeek -r capture.pcap local.zeek         # With script
zeek -Cr capture.pcap                   # Ignore checksums

OPTIONS#

-i interface        Live capture
-r file.pcap        Read pcap
-C                  Ignore checksums
-f "filter"         BPF filter
-N                  Print loaded scripts
-w file.pcap        Write raw packets
--prefix=dir        Output directory

LOG FILES#


            

COMMON LOGS#

conn.log            # Connection summary
dns.log             # DNS queries
http.log            # HTTP requests
ssl.log             # SSL/TLS connections
files.log           # File analysis
notice.log          # Alerts and notices
weird.log           # Anomalies
smtp.log            # Email
ftp.log             # FTP sessions
ssh.log             # SSH connections
x509.log            # Certificates
pe.log              # PE executables

LOG FORMAT#

# Tab-separated values
# First line: #fields field1 field2 ...
# Second line: #types type1 type2 ...

CONN.LOG FIELDS#

ts                  # Timestamp
uid                 # Unique connection ID
id.orig_h           # Source IP
id.orig_p           # Source port
id.resp_h           # Destination IP
id.resp_p           # Destination port
proto               # Protocol (tcp/udp/icmp)
service             # Detected service
duration            # Connection duration
orig_bytes          # Bytes from source
resp_bytes          # Bytes from destination
conn_state          # Connection state
missed_bytes        # Missed bytes
history             # Connection history
orig_pkts           # Packets from source
resp_pkts           # Packets to source

CONNECTION STATES#

S0      Connection attempt, no reply
S1      Connection established, not terminated
SF      Normal establishment and termination
REJ     Connection rejected
S2      Established, close attempt by originator
S3      Established, close attempt by responder
RSTO    Established, reset by originator
RSTR    Established, reset by responder
RSTOS0  Originator sent SYN then RST
RSTRH   Responder sent RST with no handshake
SH      Originator sent SYN ACK, then FIN
SHR     Responder sent SYN ACK, then FIN
OTH     No SYN, midstream traffic

ZEEK-CUT#


            

BASIC USAGE#

cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p
cat http.log | zeek-cut host uri
cat dns.log | zeek-cut query answers

WITH TIMESTAMPS#

cat conn.log | zeek-cut -d ts id.orig_h id.resp_h
# -d converts timestamps to readable format

USEFUL QUERIES#


            

CONNECTIONS#

# Top talkers
cat conn.log | zeek-cut id.orig_h | sort | uniq -c | sort -rn | head

# Connections by port
cat conn.log | zeek-cut id.resp_p | sort | uniq -c | sort -rn | head

# Long duration connections
cat conn.log | zeek-cut duration id.orig_h id.resp_h | sort -rn | head

# Large data transfers
cat conn.log | zeek-cut orig_bytes resp_bytes id.orig_h id.resp_h | sort -rn | head

DNS#

# All queries
cat dns.log | zeek-cut query | sort | uniq -c | sort -rn

# Queries by source
cat dns.log | zeek-cut id.orig_h query | sort | uniq

# Failed queries (NXDOMAIN)
cat dns.log | zeek-cut query rcode | grep NXDOMAIN

# TXT records (potential tunneling)
cat dns.log | zeek-cut query qtype | grep TXT

HTTP#

# All requested URLs
cat http.log | zeek-cut host uri

# POST requests
cat http.log | zeek-cut method host uri | grep POST

# User agents
cat http.log | zeek-cut user_agent | sort | uniq -c | sort -rn

# Response codes
cat http.log | zeek-cut status_code | sort | uniq -c | sort -rn

# Executables downloaded
cat http.log | zeek-cut host uri | grep -E "\.(exe|dll|bat|ps1)"

SSL/TLS#

# Certificates
cat ssl.log | zeek-cut server_name issuer subject

# SSL versions
cat ssl.log | zeek-cut version | sort | uniq -c

# Self-signed certificates
cat x509.log | zeek-cut certificate.issuer certificate.subject | awk '$1==$2'

FILES#

# All files
cat files.log | zeek-cut filename mime_type md5

# Executables
cat files.log | zeek-cut filename mime_type | grep "executable"

# By file type
cat files.log | zeek-cut mime_type | sort | uniq -c | sort -rn

NOTICE.LOG#

# All alerts
cat notice.log | zeek-cut note msg

SCRIPTS#


            

LOCATION#

/opt/zeek/share/zeek/
/usr/share/zeek/

COMMON SCRIPTS#

local.zeek              # Local customizations
base/                   # Core functionality
policy/                 # Additional policies

ENABLE SCRIPT#

# In local.zeek
@load policy/protocols/ssh/detect-bruteforcing
@load policy/frameworks/files/hash-all-files
@load policy/frameworks/intel/seen

INTEL FRAMEWORK#


            

CREATE INTEL FILE#

# intel.dat
#fields	indicator	indicator_type	meta.source
malware.com	Intel::DOMAIN	Threat Feed
1.2.3.4	Intel::ADDR	Blocklist

LOAD INTEL#

# In local.zeek
@load frameworks/intel/seen
@load frameworks/intel/do_notice
redef Intel::read_files += { "/opt/zeek/intel/intel.dat" };

FILE EXTRACTION#


            

ENABLE EXTRACTION#

# In local.zeek
@load policy/frameworks/files/extract-all-files
redef FileExtract::prefix = "/opt/zeek/extracted/";

SPECIFIC TYPES#

redef FileExtract::extract_types = {
    "application/x-dosexec",
    "application/x-executable",
    "application/pdf"
};

PACKAGE MANAGER#


            

ZKG (Zeek Package Manager)#

zkg install package_name
zkg remove package_name
zkg list
zkg search keyword
zkg refresh
zkg install ja3                      # JA3 fingerprinting
zkg install hassh                    # SSH fingerprinting
zkg install bzar                     # ATT&CK detection

JA3 FINGERPRINTING#

# After installing ja3 package
# Check ssl.log for ja3 and ja3s fields

cat ssl.log | zeek-cut ja3 ja3s server_name

HUNTING QUERIES#


            

BEACONING#

cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p | \
sort | uniq -c | sort -rn | head -20

DNS TUNNELING#

cat dns.log | zeek-cut query | awk '{print length, $0}' | \
sort -rn | head -20

C2 DETECTION#

# Long connections to unusual ports
cat conn.log | zeek-cut duration id.resp_p id.resp_h | \
awk '$1 > 3600 && $2 > 1024' | sort -rn

LATERAL MOVEMENT#

# SMB connections
cat conn.log | zeek-cut id.orig_h id.resp_h service | grep smb

# RDP connections
cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p | grep 3389

QUICK REFERENCE#

zeek -r file.pcap                    # Process pcap
zeek -i eth0                         # Live capture
cat conn.log | zeek-cut fields       # Extract fields
cat conn.log | zeek-cut -d ts field  # With timestamps
zkg install package                  # Install package

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.