ZEEK
Zeek (formerly Bro) is a network analysis framework. Essential for network security monitoring and forensics.
INSTALLATION#
# Ubuntu/Debian apt install zeek # From source git clone --recursive https://github.com/zeek/zeek ./configure && make && make install
BASIC USAGE#
LIVE CAPTURE#
zeek -i eth0 # Monitor interface zeek -i eth0 local.zeek # With script zeek -i eth0 -C # Ignore checksums
PROCESS PCAP#
zeek -r capture.pcap # Read pcap zeek -r capture.pcap local.zeek # With script zeek -Cr capture.pcap # Ignore checksums
OPTIONS#
-i interface Live capture -r file.pcap Read pcap -C Ignore checksums -f "filter" BPF filter -N Print loaded scripts -w file.pcap Write raw packets --prefix=dir Output directory
LOG FILES#
COMMON LOGS#
conn.log # Connection summary dns.log # DNS queries http.log # HTTP requests ssl.log # SSL/TLS connections files.log # File analysis notice.log # Alerts and notices weird.log # Anomalies smtp.log # Email ftp.log # FTP sessions ssh.log # SSH connections x509.log # Certificates pe.log # PE executables
LOG FORMAT#
# Tab-separated values # First line: #fields field1 field2 ... # Second line: #types type1 type2 ...
CONN.LOG FIELDS#
ts # Timestamp uid # Unique connection ID id.orig_h # Source IP id.orig_p # Source port id.resp_h # Destination IP id.resp_p # Destination port proto # Protocol (tcp/udp/icmp) service # Detected service duration # Connection duration orig_bytes # Bytes from source resp_bytes # Bytes from destination conn_state # Connection state missed_bytes # Missed bytes history # Connection history orig_pkts # Packets from source resp_pkts # Packets to source
CONNECTION STATES#
S0 Connection attempt, no reply S1 Connection established, not terminated SF Normal establishment and termination REJ Connection rejected S2 Established, close attempt by originator S3 Established, close attempt by responder RSTO Established, reset by originator RSTR Established, reset by responder RSTOS0 Originator sent SYN then RST RSTRH Responder sent RST with no handshake SH Originator sent SYN ACK, then FIN SHR Responder sent SYN ACK, then FIN OTH No SYN, midstream traffic
ZEEK-CUT#
BASIC USAGE#
cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p cat http.log | zeek-cut host uri cat dns.log | zeek-cut query answers
WITH TIMESTAMPS#
cat conn.log | zeek-cut -d ts id.orig_h id.resp_h # -d converts timestamps to readable format
USEFUL QUERIES#
CONNECTIONS#
# Top talkers cat conn.log | zeek-cut id.orig_h | sort | uniq -c | sort -rn | head # Connections by port cat conn.log | zeek-cut id.resp_p | sort | uniq -c | sort -rn | head # Long duration connections cat conn.log | zeek-cut duration id.orig_h id.resp_h | sort -rn | head # Large data transfers cat conn.log | zeek-cut orig_bytes resp_bytes id.orig_h id.resp_h | sort -rn | head
DNS#
# All queries cat dns.log | zeek-cut query | sort | uniq -c | sort -rn # Queries by source cat dns.log | zeek-cut id.orig_h query | sort | uniq # Failed queries (NXDOMAIN) cat dns.log | zeek-cut query rcode | grep NXDOMAIN # TXT records (potential tunneling) cat dns.log | zeek-cut query qtype | grep TXT
HTTP#
# All requested URLs cat http.log | zeek-cut host uri # POST requests cat http.log | zeek-cut method host uri | grep POST # User agents cat http.log | zeek-cut user_agent | sort | uniq -c | sort -rn # Response codes cat http.log | zeek-cut status_code | sort | uniq -c | sort -rn # Executables downloaded cat http.log | zeek-cut host uri | grep -E "\.(exe|dll|bat|ps1)"
SSL/TLS#
# Certificates cat ssl.log | zeek-cut server_name issuer subject # SSL versions cat ssl.log | zeek-cut version | sort | uniq -c # Self-signed certificates cat x509.log | zeek-cut certificate.issuer certificate.subject | awk '$1==$2'
FILES#
# All files cat files.log | zeek-cut filename mime_type md5 # Executables cat files.log | zeek-cut filename mime_type | grep "executable" # By file type cat files.log | zeek-cut mime_type | sort | uniq -c | sort -rn
NOTICE.LOG#
# All alerts cat notice.log | zeek-cut note msg
SCRIPTS#
LOCATION#
/opt/zeek/share/zeek/ /usr/share/zeek/
COMMON SCRIPTS#
local.zeek # Local customizations base/ # Core functionality policy/ # Additional policies
ENABLE SCRIPT#
# In local.zeek @load policy/protocols/ssh/detect-bruteforcing @load policy/frameworks/files/hash-all-files @load policy/frameworks/intel/seen
INTEL FRAMEWORK#
CREATE INTEL FILE#
# intel.dat #fields indicator indicator_type meta.source malware.com Intel::DOMAIN Threat Feed 1.2.3.4 Intel::ADDR Blocklist
LOAD INTEL#
# In local.zeek
@load frameworks/intel/seen
@load frameworks/intel/do_notice
redef Intel::read_files += { "/opt/zeek/intel/intel.dat" };
FILE EXTRACTION#
ENABLE EXTRACTION#
# In local.zeek @load policy/frameworks/files/extract-all-files redef FileExtract::prefix = "/opt/zeek/extracted/";
SPECIFIC TYPES#
redef FileExtract::extract_types = {
"application/x-dosexec",
"application/x-executable",
"application/pdf"
};
PACKAGE MANAGER#
ZKG (Zeek Package Manager)#
zkg install package_name zkg remove package_name zkg list zkg search keyword zkg refresh
POPULAR PACKAGES#
zkg install ja3 # JA3 fingerprinting zkg install hassh # SSH fingerprinting zkg install bzar # ATT&CK detection
JA3 FINGERPRINTING#
# After installing ja3 package # Check ssl.log for ja3 and ja3s fields cat ssl.log | zeek-cut ja3 ja3s server_name
HUNTING QUERIES#
BEACONING#
cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p | \ sort | uniq -c | sort -rn | head -20
DNS TUNNELING#
cat dns.log | zeek-cut query | awk '{print length, $0}' | \
sort -rn | head -20
C2 DETECTION#
# Long connections to unusual ports cat conn.log | zeek-cut duration id.resp_p id.resp_h | \ awk '$1 > 3600 && $2 > 1024' | sort -rn
LATERAL MOVEMENT#
# SMB connections cat conn.log | zeek-cut id.orig_h id.resp_h service | grep smb # RDP connections cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p | grep 3389
QUICK REFERENCE#
zeek -r file.pcap # Process pcap zeek -i eth0 # Live capture cat conn.log | zeek-cut fields # Extract fields cat conn.log | zeek-cut -d ts field # With timestamps zkg install package # Install package
ZEEK CHEATSHEET
===============
Source: https://cheatsheet.johlem.net
Zeek (formerly Bro) is a network analysis framework.
Essential for network security monitoring and forensics.
INSTALLATION
------------
# Ubuntu/Debian
apt install zeek
# From source
git clone --recursive https://github.com/zeek/zeek
./configure && make && make install
BASIC USAGE
===========
LIVE CAPTURE
------------
zeek -i eth0 # Monitor interface
zeek -i eth0 local.zeek # With script
zeek -i eth0 -C # Ignore checksums
PROCESS PCAP
------------
zeek -r capture.pcap # Read pcap
zeek -r capture.pcap local.zeek # With script
zeek -Cr capture.pcap # Ignore checksums
OPTIONS
-------
-i interface Live capture
-r file.pcap Read pcap
-C Ignore checksums
-f "filter" BPF filter
-N Print loaded scripts
-w file.pcap Write raw packets
--prefix=dir Output directory
LOG FILES
=========
COMMON LOGS
-----------
conn.log # Connection summary
dns.log # DNS queries
http.log # HTTP requests
ssl.log # SSL/TLS connections
files.log # File analysis
notice.log # Alerts and notices
weird.log # Anomalies
smtp.log # Email
ftp.log # FTP sessions
ssh.log # SSH connections
x509.log # Certificates
pe.log # PE executables
LOG FORMAT
----------
# Tab-separated values
# First line: #fields field1 field2 ...
# Second line: #types type1 type2 ...
CONN.LOG FIELDS
---------------
ts # Timestamp
uid # Unique connection ID
id.orig_h # Source IP
id.orig_p # Source port
id.resp_h # Destination IP
id.resp_p # Destination port
proto # Protocol (tcp/udp/icmp)
service # Detected service
duration # Connection duration
orig_bytes # Bytes from source
resp_bytes # Bytes from destination
conn_state # Connection state
missed_bytes # Missed bytes
history # Connection history
orig_pkts # Packets from source
resp_pkts # Packets to source
CONNECTION STATES
-----------------
S0 Connection attempt, no reply
S1 Connection established, not terminated
SF Normal establishment and termination
REJ Connection rejected
S2 Established, close attempt by originator
S3 Established, close attempt by responder
RSTO Established, reset by originator
RSTR Established, reset by responder
RSTOS0 Originator sent SYN then RST
RSTRH Responder sent RST with no handshake
SH Originator sent SYN ACK, then FIN
SHR Responder sent SYN ACK, then FIN
OTH No SYN, midstream traffic
ZEEK-CUT
========
BASIC USAGE
-----------
cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p
cat http.log | zeek-cut host uri
cat dns.log | zeek-cut query answers
WITH TIMESTAMPS
---------------
cat conn.log | zeek-cut -d ts id.orig_h id.resp_h
# -d converts timestamps to readable format
USEFUL QUERIES
==============
CONNECTIONS
-----------
# Top talkers
cat conn.log | zeek-cut id.orig_h | sort | uniq -c | sort -rn | head
# Connections by port
cat conn.log | zeek-cut id.resp_p | sort | uniq -c | sort -rn | head
# Long duration connections
cat conn.log | zeek-cut duration id.orig_h id.resp_h | sort -rn | head
# Large data transfers
cat conn.log | zeek-cut orig_bytes resp_bytes id.orig_h id.resp_h | sort -rn | head
DNS
---
# All queries
cat dns.log | zeek-cut query | sort | uniq -c | sort -rn
# Queries by source
cat dns.log | zeek-cut id.orig_h query | sort | uniq
# Failed queries (NXDOMAIN)
cat dns.log | zeek-cut query rcode | grep NXDOMAIN
# TXT records (potential tunneling)
cat dns.log | zeek-cut query qtype | grep TXT
HTTP
----
# All requested URLs
cat http.log | zeek-cut host uri
# POST requests
cat http.log | zeek-cut method host uri | grep POST
# User agents
cat http.log | zeek-cut user_agent | sort | uniq -c | sort -rn
# Response codes
cat http.log | zeek-cut status_code | sort | uniq -c | sort -rn
# Executables downloaded
cat http.log | zeek-cut host uri | grep -E "\.(exe|dll|bat|ps1)"
SSL/TLS
-------
# Certificates
cat ssl.log | zeek-cut server_name issuer subject
# SSL versions
cat ssl.log | zeek-cut version | sort | uniq -c
# Self-signed certificates
cat x509.log | zeek-cut certificate.issuer certificate.subject | awk '$1==$2'
FILES
-----
# All files
cat files.log | zeek-cut filename mime_type md5
# Executables
cat files.log | zeek-cut filename mime_type | grep "executable"
# By file type
cat files.log | zeek-cut mime_type | sort | uniq -c | sort -rn
NOTICE.LOG
----------
# All alerts
cat notice.log | zeek-cut note msg
SCRIPTS
=======
LOCATION
--------
/opt/zeek/share/zeek/
/usr/share/zeek/
COMMON SCRIPTS
--------------
local.zeek # Local customizations
base/ # Core functionality
policy/ # Additional policies
ENABLE SCRIPT
-------------
# In local.zeek
@load policy/protocols/ssh/detect-bruteforcing
@load policy/frameworks/files/hash-all-files
@load policy/frameworks/intel/seen
INTEL FRAMEWORK
===============
CREATE INTEL FILE
-----------------
# intel.dat
#fields indicator indicator_type meta.source
malware.com Intel::DOMAIN Threat Feed
1.2.3.4 Intel::ADDR Blocklist
LOAD INTEL
----------
# In local.zeek
@load frameworks/intel/seen
@load frameworks/intel/do_notice
redef Intel::read_files += { "/opt/zeek/intel/intel.dat" };
FILE EXTRACTION
===============
ENABLE EXTRACTION
-----------------
# In local.zeek
@load policy/frameworks/files/extract-all-files
redef FileExtract::prefix = "/opt/zeek/extracted/";
SPECIFIC TYPES
--------------
redef FileExtract::extract_types = {
"application/x-dosexec",
"application/x-executable",
"application/pdf"
};
PACKAGE MANAGER
===============
ZKG (Zeek Package Manager)
--------------------------
zkg install package_name
zkg remove package_name
zkg list
zkg search keyword
zkg refresh
POPULAR PACKAGES
----------------
zkg install ja3 # JA3 fingerprinting
zkg install hassh # SSH fingerprinting
zkg install bzar # ATT&CK detection
JA3 FINGERPRINTING
==================
# After installing ja3 package
# Check ssl.log for ja3 and ja3s fields
cat ssl.log | zeek-cut ja3 ja3s server_name
HUNTING QUERIES
===============
BEACONING
---------
cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p | \
sort | uniq -c | sort -rn | head -20
DNS TUNNELING
-------------
cat dns.log | zeek-cut query | awk '{print length, $0}' | \
sort -rn | head -20
C2 DETECTION
------------
# Long connections to unusual ports
cat conn.log | zeek-cut duration id.resp_p id.resp_h | \
awk '$1 > 3600 && $2 > 1024' | sort -rn
LATERAL MOVEMENT
----------------
# SMB connections
cat conn.log | zeek-cut id.orig_h id.resp_h service | grep smb
# RDP connections
cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p | grep 3389
QUICK REFERENCE
---------------
zeek -r file.pcap # Process pcap
zeek -i eth0 # Live capture
cat conn.log | zeek-cut fields # Extract fields
cat conn.log | zeek-cut -d ts field # With timestamps
zkg install package # Install package
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.