Install
$ agentstack add skill-meltedinhex-analyst-ai-pack-building-zeek-analytics-for-hunting ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Building Zeek Analytics for Hunting
When to Use
- You have Zeek logs (conn.log, dns.log, http.log, ssl.log, files.log) and want to build hunting
analytics: long-lived connections, rare JA3 fingerprints, suspicious file downloads, and beaconing.
- You want repeatable detections expressed as Zeek scripts or log-analysis queries.
Do not use Zeek to actively probe hosts — it is passive analysis of captured/sensor traffic.
Prerequisites
- Zeek logs in TSV or JSON (or a running Zeek sensor). The script analyzes exported logs.
Workflow
Step 1: Analyze a Zeek log for anomalies
python scripts/analyst.py analyze conn.log --kind conn
For conn, surfaces long-duration and high-byte connections; for ssl, counts JA3 rarity; for http, flags executable/script downloads and rare user-agents; for dns, flags long/high-entropy queries.
Step 2: Express the logic as a Zeek script (optional)
Translate a confirmed pattern into a Zeek script using the appropriate event (connection_state_remove, ssl_established, http_reply).
Step 3: Confirm
Corroborate anomalies with destination reputation and other logs (pivot by uid).
Step 4: Operationalize
Stage the Zeek script or scheduled log query as a durable detection.
Validation
- The analyzer parses both TSV (
#fields) and JSON Zeek logs. - Surfaced anomalies match the chosen log kind's fields.
- JA3 rarity and long-connection logic are computed correctly.
Pitfalls
- TSV header (
#fields) parsing — column order varies by deployment. - Backups/updates producing benign long/large connections.
- JA3 collisions across legitimate clients.
References
- See [
references/api-reference.md](references/api-reference.md) for the analyzer. - Zeek docs and log-format references (linked in frontmatter).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: meltedinhex
- Source: meltedinhex/analyst-ai-pack
- License: Apache-2.0
- Homepage: https://meltedinhex.com/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.