Re: ZEEK AS AN IDS
edX <[email protected]> Thu, 24 Oct 2019 09:27:48 +0300
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAArApxKbufy5tdmfFUNV6pw2cFjiUC7G9KqvmvK+Ao74Dcn23A@mail.gmail.com> |
Thanks, I'll check it out. edX On Wed, Oct 23, 2019 at 4:41 PM Richard Bejtlich <[email protected]> wrote: > I just Googled > > bro sql injection detection > > and this paper was the second result, right after a link to the Bro SQL > injection detection script. > > > https://www.sans.org/reading-room/whitepapers/detection/web-application-attack-analysis-bro-ids-34042 > > > You might have to look for Bro references as the Zeek rename is only a > year old. > > Sincerely, > > Richard > > On Wed, Oct 23, 2019 at 9:26 AM edX <[email protected]> wrote: > >> I have done some research on detecting ssh bruteforce attacks. I found >> resource from hold my beer blog. >> >> edx0004. >> >> On Wed, Oct 23, 2019 at 3:49 PM Richard Bejtlich <[email protected]> >> wrote: >> >>> Hello, >>> >>> What research have you done so far? >>> >>> Richard >>> >>> On Wed, Oct 23, 2019 at 4:04 AM edX <[email protected]> wrote: >>> >>>> Hello! I am an intermediate zeek user. I would like a walk-through on >>>> how i can use zeek to detect different types of attacks such as sql >>>> injection, ddos, man in the middle attacks and the likes. >>>> Thanks. >>>> _______________________________________________ >>>> Zeek mailing list >>>> [email protected] >>>> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek >>> >>> >>> >>> -- >>> Richard Bejtlich >>> Principal Security Strategist, Corelight >>> https://corelight.blog/author/richardbejtlich/ >>> >> > > -- > Richard Bejtlich > Principal Security Strategist, Corelight > https://corelight.blog/author/richardbejtlich/ > _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek