AgentStack
SKILL verified Apache-2.0 Self-run

Building Zeek Analytics For Hunting

skill-meltedinhex-analyst-ai-pack-building-zeek-analytics-for-hunting · by meltedinhex

Builds Zeek-based network hunting analytics by writing scripts and analyzing Zeek logs

No reviews yet
0 installs
11 views
0.0% view→install

Install

$ agentstack add skill-meltedinhex-analyst-ai-pack-building-zeek-analytics-for-hunting

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Building Zeek Analytics For Hunting? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Building Zeek Analytics for Hunting

When to Use

  • You have Zeek logs (conn.log, dns.log, http.log, ssl.log, files.log) and want to build hunting

analytics: long-lived connections, rare JA3 fingerprints, suspicious file downloads, and beaconing.

  • You want repeatable detections expressed as Zeek scripts or log-analysis queries.

Do not use Zeek to actively probe hosts — it is passive analysis of captured/sensor traffic.

Prerequisites

  • Zeek logs in TSV or JSON (or a running Zeek sensor). The script analyzes exported logs.

Workflow

Step 1: Analyze a Zeek log for anomalies

python scripts/analyst.py analyze conn.log --kind conn

For conn, surfaces long-duration and high-byte connections; for ssl, counts JA3 rarity; for http, flags executable/script downloads and rare user-agents; for dns, flags long/high-entropy queries.

Step 2: Express the logic as a Zeek script (optional)

Translate a confirmed pattern into a Zeek script using the appropriate event (connection_state_remove, ssl_established, http_reply).

Step 3: Confirm

Corroborate anomalies with destination reputation and other logs (pivot by uid).

Step 4: Operationalize

Stage the Zeek script or scheduled log query as a durable detection.

Validation

  • The analyzer parses both TSV (#fields) and JSON Zeek logs.
  • Surfaced anomalies match the chosen log kind's fields.
  • JA3 rarity and long-connection logic are computed correctly.

Pitfalls

  • TSV header (#fields) parsing — column order varies by deployment.
  • Backups/updates producing benign long/large connections.
  • JA3 collisions across legitimate clients.

References

  • See [references/api-reference.md](references/api-reference.md) for the analyzer.
  • Zeek docs and log-format references (linked in frontmatter).

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.