PCAP Data Analysis with Zeek, (Sun, Feb 12th)

This post was originally published on this site

Having full packet captures of a device or an entire network can be extremely useful. It is also a lot of data to go through and process manually. Zeek [1] can help to simplify network traffic analysis. It can also help save a lot of storage space. I'll be going through and processing some PCAP data collected from my honeypot. First, we need to install a couple tools to process the PCAP data. I started with a fully updated Ubuntu 22.04.1 LTS desktop [2]. The steps to get our Zeek data from raw PCAPs will be:

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.