| name | detecting-network-anomalies-with-zeek |
| description | Use when deploying and configuring Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response. |
| domain | cybersecurity |
| tags | ["network-security","zeek","network-monitoring","anomaly-detection","threat-hunting"] |
| subdomain | network-security |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-03","PR.DS-02"] |
Detecting Network Anomalies With Zeek
Overview
Cybersecurity skill for detecting network anomalies with zeek. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"detecting network anomalies with zeek"
-
"Deploys and configures Zeek (formerly Bro) network security monitor to passively"
-
Deploying passive network security monitoring at key network choke points for continuous visibility
-
Generating structured connection, DNS, HTTP, SSL, and file transfer logs for SIEM ingestion and threat hunting
-
Writing custom Zeek scripts to detect organization-specific threats, policy violations, or beaconing behavior
-
Performing retrospective analysis on network metadata to investigate security incidents
-
Complementing IDS solutions with protocol-level metadata analysis that signature-based tools may miss
Do not use as a replacement for inline IDS/IPS that can actively block traffic, for monitoring encrypted payloads without TLS inspection, or on endpoints where host-based agents are more appropriate.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Zeek 6.0+ installed from source or package manager (
zeek --version)
- Network interface configured on a span port, network tap, or virtual switch mirror for passive capture
- Sufficient disk storage for log files (estimate 1-5 GB/day per 100 Mbps of monitored traffic)
- Familiarity with Zeek's scripting language for writing custom detections
- Log aggregation system (Splunk, Elastic, Graylog) for centralized analysis
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}