Remnux is now on 20.04 so look out fellow future people. Thanks for this John.
@alanmarkkristensen28784 жыл бұрын
Fantastic series. You’re great at explaining, and you’re great at picking relevant topics! Can’t wait for tomorrow’s episode!
@jibraelaryaanentertainment12634 ай бұрын
Excellent video John. Spot on and extremely useful.
@adivasi68943 жыл бұрын
Never knew Zeek, would love to see more...Great job John.
@Marcrasq Жыл бұрын
Well crafted video, super easy to follow, and great explanation of each command cheers.
@andrew1542212 жыл бұрын
Dude you saved my freaking life for my lab due tonight, thank you!!!
@johnvardy955911 ай бұрын
hey john great informations, the puzzle it's a bit big across tcpdump Tshark zeek brim and so on as a beginner you can't clear enough the path and what is that a SOC analyst net for NTA.
@alexanderjean97843 жыл бұрын
Helped me tremendously! Thank you, John.
@afeefshaikh78762 жыл бұрын
10:45 How do you go back and forth between the terminal and the logs? I’m on Windows btw
@SecHubb2 жыл бұрын
Nothing fancy, I’m just quitting out of viewing the file with the less command and being taken back to the terminal.
@Lykos-i2m2 жыл бұрын
Learned a lot from the video, thanks for sharing your valuable knowledge with the world!
@hptc4400 Жыл бұрын
Awesome content... Really appreciated. One question though. Why none of the public IP addresses were in the source address column (id.orig_h) in the conn.log? Does that mean no ingress communication took place or is that of Zeek records it traffic?
@ibejoe77194 ай бұрын
Kaching....on the money bro job well done thanks
@dougthebugwrx4 жыл бұрын
Clear and concise instructions. Awesome thank you .
@impeccablestudio8442 жыл бұрын
I am getting the below error in the last step of the process and i havt found any sourse which provides the solutions . Please have a look and let me know if there is anything i can do . "The following packages have unmet dependencies. zeek-core : Depends: libc6 (< 2.28) but 2.35-0ubuntu3 is to be installed Depends: libssl1.1 (>= 1.1.0) but it is not installable E: Unable to correct problems, you have held broken packages. "
@ipmail22242 жыл бұрын
try googling so that you can install from ppa for your distro
@abdulrahmanbasa89932 жыл бұрын
but wich one is better zeek or wireshark?
@nitaantvyas676 Жыл бұрын
Are there any cheat sheets of zeek queries?
@yungskullivan2 жыл бұрын
Thanks, John! Super helpful.
@garrettw61453 жыл бұрын
Excellent Approach! Super useful!
@6Karaboudjan9 Жыл бұрын
how to enable it on fedora
@gamalielsankaytshiswakamar9612 жыл бұрын
Outstanding explanation
@lifechangerstore4 жыл бұрын
As a blue team, its like earmilk. Very very good.
@oguzylmaz51884 жыл бұрын
Thank you for sharing such kind of invaluable info. I appreciate you.
@contacthellosew78533 жыл бұрын
Perfect Explanation ever! Thank you
@ManojKumar-yt5ne2 жыл бұрын
Thanks for your amazing video. Could you please suggest how to use python to capture network data through libpcap or winpcap?
@AjitKumar-sy9cv4 жыл бұрын
Again great explanation and good topic.. !!
@behfarmr60353 жыл бұрын
That's great! Thank you very much. Appreciated! How can generate alert instead of logs with Zeek?
@SecHubb3 жыл бұрын
For that you’ll want some kind of IDS. Suricata is a great free option for that.
@sposada00 Жыл бұрын
This is amazing stuff
@jayinfosec4 жыл бұрын
Great videos John!
@mohamedsaidani85094 жыл бұрын
Thanks man ^^ we are waiting for the next one ;)
@أحمدباسمراضيابومحسن Жыл бұрын
What is the password to decrypt the file
@rezamehrad85124 жыл бұрын
Perfect Series!
@comunidaddojo4 жыл бұрын
Very good content, thanks for sharing.
@anasshaikh57784 жыл бұрын
Hey can we install zeek in windows subsystem for Linux