In this segment we cover one of Zeek's most central concepts, the event. We discuss how events in Zeek are analogous to human network traffic analysis activities and describe how Zeek provides access to network traffic artifacts through the use of event handlers. Finally, we review several of Zeek's built-in events and discuss how they can be handled to perform various traffic analsyis tasks.
Intro to Zeek Scripting with Bricata
The goal of this course is to provide you with an introduction to Zeek (formerly Bro) the application and the programming language. While the logs Zeek produces natively can be extremely useful, its full value is realized through its scripting interface.