12 Days of Defense - Day 2: How to use Zeek for PCAP Analysis

  Рет қаралды 26,648

John Hubbard

John Hubbard

Күн бұрын

Пікірлер: 41
@RyanBro
@RyanBro 2 жыл бұрын
Remnux is now on 20.04 so look out fellow future people. Thanks for this John.
@alanmarkkristensen2878
@alanmarkkristensen2878 4 жыл бұрын
Fantastic series. You’re great at explaining, and you’re great at picking relevant topics! Can’t wait for tomorrow’s episode!
@jibraelaryaanentertainment1263
@jibraelaryaanentertainment1263 4 ай бұрын
Excellent video John. Spot on and extremely useful.
@adivasi6894
@adivasi6894 3 жыл бұрын
Never knew Zeek, would love to see more...Great job John.
@Marcrasq
@Marcrasq Жыл бұрын
Well crafted video, super easy to follow, and great explanation of each command cheers.
@andrew154221
@andrew154221 2 жыл бұрын
Dude you saved my freaking life for my lab due tonight, thank you!!!
@johnvardy9559
@johnvardy9559 11 ай бұрын
hey john great informations, the puzzle it's a bit big across tcpdump Tshark zeek brim and so on as a beginner you can't clear enough the path and what is that a SOC analyst net for NTA.
@alexanderjean9784
@alexanderjean9784 3 жыл бұрын
Helped me tremendously! Thank you, John.
@afeefshaikh7876
@afeefshaikh7876 2 жыл бұрын
10:45 How do you go back and forth between the terminal and the logs? I’m on Windows btw
@SecHubb
@SecHubb 2 жыл бұрын
Nothing fancy, I’m just quitting out of viewing the file with the less command and being taken back to the terminal.
@Lykos-i2m
@Lykos-i2m 2 жыл бұрын
Learned a lot from the video, thanks for sharing your valuable knowledge with the world!
@hptc4400
@hptc4400 Жыл бұрын
Awesome content... Really appreciated. One question though. Why none of the public IP addresses were in the source address column (id.orig_h) in the conn.log? Does that mean no ingress communication took place or is that of Zeek records it traffic?
@ibejoe7719
@ibejoe7719 4 ай бұрын
Kaching....on the money bro job well done thanks
@dougthebugwrx
@dougthebugwrx 4 жыл бұрын
Clear and concise instructions. Awesome thank you .
@impeccablestudio844
@impeccablestudio844 2 жыл бұрын
I am getting the below error in the last step of the process and i havt found any sourse which provides the solutions . Please have a look and let me know if there is anything i can do . "The following packages have unmet dependencies. zeek-core : Depends: libc6 (< 2.28) but 2.35-0ubuntu3 is to be installed Depends: libssl1.1 (>= 1.1.0) but it is not installable E: Unable to correct problems, you have held broken packages. "
@ipmail2224
@ipmail2224 2 жыл бұрын
try googling so that you can install from ppa for your distro
@abdulrahmanbasa8993
@abdulrahmanbasa8993 2 жыл бұрын
but wich one is better zeek or wireshark?
@nitaantvyas676
@nitaantvyas676 Жыл бұрын
Are there any cheat sheets of zeek queries?
@yungskullivan
@yungskullivan 2 жыл бұрын
Thanks, John! Super helpful.
@garrettw6145
@garrettw6145 3 жыл бұрын
Excellent Approach! Super useful!
@6Karaboudjan9
@6Karaboudjan9 Жыл бұрын
how to enable it on fedora
@gamalielsankaytshiswakamar961
@gamalielsankaytshiswakamar961 2 жыл бұрын
Outstanding explanation
@lifechangerstore
@lifechangerstore 4 жыл бұрын
As a blue team, its like earmilk. Very very good.
@oguzylmaz5188
@oguzylmaz5188 4 жыл бұрын
Thank you for sharing such kind of invaluable info. I appreciate you.
@contacthellosew7853
@contacthellosew7853 3 жыл бұрын
Perfect Explanation ever! Thank you
@ManojKumar-yt5ne
@ManojKumar-yt5ne 2 жыл бұрын
Thanks for your amazing video. Could you please suggest how to use python to capture network data through libpcap or winpcap?
@AjitKumar-sy9cv
@AjitKumar-sy9cv 4 жыл бұрын
Again great explanation and good topic.. !!
@behfarmr6035
@behfarmr6035 3 жыл бұрын
That's great! Thank you very much. Appreciated! How can generate alert instead of logs with Zeek?
@SecHubb
@SecHubb 3 жыл бұрын
For that you’ll want some kind of IDS. Suricata is a great free option for that.
@sposada00
@sposada00 Жыл бұрын
This is amazing stuff
@jayinfosec
@jayinfosec 4 жыл бұрын
Great videos John!
@mohamedsaidani8509
@mohamedsaidani8509 4 жыл бұрын
Thanks man ^^ we are waiting for the next one ;)
@أحمدباسمراضيابومحسن
@أحمدباسمراضيابومحسن Жыл бұрын
What is the password to decrypt the file
@rezamehrad8512
@rezamehrad8512 4 жыл бұрын
Perfect Series!
@comunidaddojo
@comunidaddojo 4 жыл бұрын
Very good content, thanks for sharing.
@anasshaikh5778
@anasshaikh5778 4 жыл бұрын
Hey can we install zeek in windows subsystem for Linux
@rckrs-jf8lb
@rckrs-jf8lb 4 жыл бұрын
Excelent information.
@abdirahmanbadri2943
@abdirahmanbadri2943 3 жыл бұрын
helpful tricks and tools thanks allot
@abhigyanapandey6454
@abhigyanapandey6454 3 жыл бұрын
wanna hear a secret,cap? ur AWESOME
@kapoof2
@kapoof2 3 жыл бұрын
Wow he went X-Games mode at the end.
The Lost World: Living Room Edition
0:46
Daniel LaBelle
Рет қаралды 27 МЛН
Жездуха 42-серия
29:26
Million Show
Рет қаралды 2,6 МЛН
Open Source Cyber Threat Hunting with Zeek: Getting Started
13:59
Using Zeek/Bro To Discover Network TTPs of MITRE ATT&CK™ Part 1
1:02:18
Analyzing PCAP with Zeek - HTB Sherlocks - KnockKnock
1:31:13
How To Use The Elastic Stack as a SIEM - John Hubbard
1:14:17
John Hubbard
Рет қаралды 56 М.
Packet & Log Analysis with Zeek P1 | TryHackMe Zeek
24:07
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 4,2 М.
Practical Malware Analysis Essentials for Incident Responders
50:49
RSA Conference
Рет қаралды 151 М.
Advanced Zeek Usage  Scripting and Framework
58:22
SANS Digital Forensics and Incident Response
Рет қаралды 8 М.
Wireshark - Malware traffic Analysis
16:01
Hack eXPlorer
Рет қаралды 206 М.
Detect Hackers & Malware on your Computer (literally for free)
16:38