Category: Open Source
-
Using Logitech Brio In 4K In OBS On A 2019 Intel MacBook Pro
I do a fair amount of recording for my YouTube channel on a MacBook Pro, circa 2019. It has the Intel chip. Nothing I found online worked exactly for me when I…
-
Zeek Clustering How-To Video
I put together a Zeek clustering video over at Youtube (https://youtu.be/g-QvpYHgh1c). You can get to the slides through: https://docs.google.com/presentation/d/1HHHF4-FNhoSuy-YPMOWka3EGvfOW7CJAFeS9VHxBg_E/edit?usp=sharing The source code is available at: https://github.com/corelight/CVE-2022-24491
-
Using Zeek Signatures To Detect CVEs
I put a video together (https://www.youtube.com/watch?v=PcXjkUt3rZA) discussing a method I have used to detect CVEs using just Zeek signatures: https://docs.zeek.org/en/master/frameworks/signatures.html This method is useful when trying to detect a CVE exploit in…
-
Zeek’s suspend_processing Quirk With PCAPs
In the comments of an earlier blog: … we found an interesting situation. Even when you call “suspend_processing” in zeek_init, like this: … Zeek will still process the first packet. The “new_connection”…
-
Top 10 Mostly All Free And Open Source Podcast Creator Tools
Wonder what software we use to produce https://ecrimebytes.com? Here you go. Click on the application name to go to their website. Audacity, Blender, GIMP, and Shotcut are open source. If you have…
-
How To Profile A Zeek Spicy Protocol Analyzer
This is a good page over at the Zeek Spicy Wiki on how to profile protocol analyzers: https://github.com/zeek/spicy/wiki/Performance-profiling-of-Spicy-parsers
-
Zeek Spicy IPSec Protocol Analyzer Update – v0.2.17
An update in the protocol analyzer now makes it Zeek v5.2 ready. You can view more here: https://github.com/corelight/zeek-spicy-ipsec You can install the latest version with the following command:
-
My Zeek How-To Video Playlist
Here is a playlist I put together of just my Zeek How-To videos:
-
Zeek Spicy OSPF Packet Analyzer Update – v0.1.4
An update in the packet analyzer now makes it Zeek v5.2 ready. You can view more here: https://github.com/corelight/zeek-spicy-ospf You can install the latest version with the following command:
-
YouTube Video For How To Connect Zeek To Python Is Up!
Here is a short video I put together to show how to pass PCAP data from Zeek through Python and back to Zeek. The original instructions I wrote can be found here:…