Packages

zeek-plugin-tds

By amzn

Plugin that enables parsing of the Tabular Data Stream (TDS) protocol

zeek-postgresql

By 0xxon

A PostgreSQL reader and writer for Bro.

zeek-print-log-info

By jsiwek

Gathers and prints field descriptions for all Zeek logs. The default output format is CSV files.

zeek-quic

By corelight

Detects the Google QUIC (GQUIC) protocol and adds "gquic" to conn.log's "service" field.

zeek-sniffpass

By cybera

Sniffpass will alert on cleartext passwords discovered in HTTP POST requests

zeek-ssh-interesting-hostnames-with-known

By dopheide

This script replaces the default ssh/interesting-hostnames and reduces the number of asyncrhonous when() calls made by Zeek.

zeek-sumstats-counttable

By 0xxon

Two-dimensional buckets for sumstats (count occurences per $str).

zeek-test-package

By jsiwek

An example Zeek package for testing purposes.

zeek-testimony-plugin

By sirinsoftware

This plugin provides Testimony support for Zeek.

zeek-tls-log-alternative

By 0xxon

"This package generates a file called tls.log. The difference from ssl.log is that it is much more focused on logging all kinds of protocol features. This can be interesting for academic purposes - or if one is just interested in more information about specific features used in local TLS traffic."

zeek-vast

By tenzir

A package that enables Zeek to communicate with VAST

zeek-zip-analyzer

By reservoirlabs

A ZIP file analyzer for Zeek

zerologon

By corelight

Detects Zerologon (CVE-2020-1472) attempts and exploits.

ztest

By corelight

A Zeek Unit Testing Framework

Page 8 of 8, showing 14 record(s) out of 154 total