Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
Analyze Zeek network logs to identify lateral movement techniques including
SMB admin share access, DCE/RPC remote service creation, NTLM account spray,
Kerberos ticket anomalies, and large internal data transfers indicative
of staging or exfiltration between hosts.
When to Use
Hunting for lateral movement after an initial compromise indicator is found on one endpoint
Investigating suspected NTLM account spray or Pass-the-Ticket attacks across the internal network
Monitoring SMB traffic for unauthorized file transfers to admin shares (C$, ADMIN$, IPC$)
Detecting remote service execution via DCE/RPC (PsExec, schtasks, WMI lateral patterns)
Building alerting rules for internal network anomalies in a Zeek-based NSMP deployment
Performing post-incident timeline reconstruction using Zeek logs as a network-level evidence source
Do not use as a standalone detection mechanism. Zeek sees network traffic only; combine with endpoint telemetry (Sysmon, EDR) for full visibility. Encrypted SMB3 traffic may limit Zeek's visibility into file-level details.
Detection Gaps & Validation
SMB3 encryption blinds file-level logs: with SMB3 encryption negotiated, smb_files.log/smb_mapping.log lose path and filename detail, so admin-share write rules silently miss. Fall back to conn.log 445 volume/asymmetry between internal hosts and flag the encrypted SMB sessions themselves rather than concluding "no lateral movement."
WMI/DCOM and WinRM evade the svcctl signature: PsExec hits svcctl, but WMIExec uses IWbemServices over 135+ephemeral DCOM and WinRM rides 5985/5986 (often as HTTP/SOAP). Grep dce_rpc.log for IWbemServices/IRemUnknown2 and watch WinRM ports, not just svcctl/atsvc.
Kerberos (Pass-the-Ticket/overpass) leaves no NTLM trail: the NTLM-spray script won't fire when attackers use Kerberos. Add kerberos.log checks for anomalous TGS requests, encryption downgrade (etype RC4/0x17), and one account requesting tickets for many SPNs/hosts.
Spray threshold is evasion-prone:spray_threshold=3 over 5min misses slow spraying across hours. Widen the &create_expire window and track distinct id.resp_h per username over a longer epoch; tune up to cut FPs from vuln scanners/SCCM.
Validate detections fire: in a lab run PsExec and confirm the chain — smb_files.logSMB::FILE_WRITE of the service binary, then dce_rpc.logsvcctlCreateServiceW, then a notice.logAdmin_Share_Access/NTLM_Account_Spray. Cross-check with Sysmon EID 1 on the target. No notice means the analyzer isn't loaded or the SPAN misses the internal VLAN.
FP tuning: exclude legitimate admin jump hosts, SCCM/patch servers, and backup agents that touch admin shares and many hosts by design before alerting.
Prerequisites
Zeek 6.0+ deployed on a network tap or SPAN port monitoring internal VLAN traffic
Zeek SMB analyzer enabled (loaded by default: @load base/protocols/smb)
Access to Zeek log directory (default: /opt/zeek/logs/current/)
Familiarity with Zeek TSV log format (fields separated by \t, header lines prefixed with #)
Workflow
Step 1: Verify Zeek Log Collection
Confirm that Zeek is producing the required log files for lateral movement detection:
# Check that all required analyzers are producing logsls -la /opt/zeek/logs/current/conn.log
ls -la /opt/zeek/logs/current/smb_mapping.log
ls -la /opt/zeek/logs/current/smb_files.log
ls -la /opt/zeek/logs/current/dce_rpc.log
ls -la /opt/zeek/logs/current/kerberos.log
ls -la /opt/zeek/logs/current/ntlm.log
# Quick field check on conn.log
zeek-cut id.orig_h id.resp_h id.resp_p proto service < /opt/zeek/logs/current/conn.log | head -20
Step 2: Parse conn.log for Internal Lateral Patterns
Identify connections between internal hosts on lateral-movement-associated ports:
Monitor for remote service creation and scheduled task registration via DCE/RPC:
# Look for service control manager operations (PsExec pattern)
zeek-cut ts id.orig_h id.resp_h endpoint operation \
< /opt/zeek/logs/current/dce_rpc.log \
| grep -iE '(svcctl|atsvc|ITaskSchedulerService)'
Step 5: Detect NTLM Account Spray
Analyze ntlm.log for authentication anomalies indicating credential reuse.
Zeek's ntlm.log does not expose password hashes, so this detection identifies
a single account authenticating to many hosts in a short window — the network
signature of credential spraying tools like CrackMapExec:
Test with a known PsExec execution in a lab: expect to see SMB FILE_WRITE of the service binary followed by DCE/RPC svcctl CreateService
Validate NTLM log parsing by performing a test authentication and confirming username, domain, and success fields are captured; verify the NTLM Account Spray Zeek script generates a notice.log entry when the spray threshold is exceeded
Cross-reference Zeek alerts with Sysmon Event ID 1 (Process Creation) on the target host to confirm end-to-end detection
Verify the agent correctly handles both TSV and JSON Zeek log formats