You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Feb 1, 2026. It is now read-only.
ZafirAnsari edited this page Oct 25, 2021
·
1 revision
The folder 'Attack case' contains logs generated by Zeek-Agent from an attack. You can upload the data to elasticsearch using 'es_load.py'. The compromised file is 'syslog' which you can search on and trace the attack, you might observe a note from the attacker when clicking on one of the process nodes. The note will be present in the 'message.txt' file. The freeze exploration command will prove to be helpful to see node details without exploring them.