Zeek

4.2.1

2.4.0

8

Microknoppix

2

332.319364

10.10.57.178

38712

What is the total number of the sent and received packets from source port 38706? 

20

Investigate the notice.log. What is the number of unique events?

1413

1410

astaro_vineyard

17

jaalam.net

1109

Investigate the sample.pcap file with 103.zeek script. Investigate the terminal output. What is the number of the detected new connections? 

87

Investigate the ftp.pcap file with ftp-admin.sig signature and  201.zeek script. Investigate the signatures.log file. What is the number of signature hits? 

1401

731

498

Investigate the ftp-brute.pcap file with "/opt/zeek/share/zeek/policy/protocols/ftp/detect-bruteforcing.zeek" script. Investigate the notice.log file. What is the total number of brute-force detections? 

2

IN_HOST_HEADER

knr.exe

cc28e40b46237ab6d5282199ef78c464

Microsoft NCSI

BroZeek

Chicago

23.77.86.54

4