Zeek - Packet inspection
Inspect network traffic in three real-life incident cases (Suspicious DNS Query, Phishing Campaign, and Log4j) with Zeek.
By Ren Sie
Refer to Zeek Exercises for the challenge room on TryHackMe Case #1 - Anomalous DNS Scenario An alert triggered: "Anomalous DNS Activity". Inspect the PCAP and retrieve the artefacts to confirm this alert is a true positive. Task During this exercise, we will use the Zeek command with the -Cr...
[Read More]