Skip to content
This repository was archived by the owner on Feb 1, 2026. It is now read-only.

Tutorial Attack case

ZafirAnsari edited this page Oct 25, 2021 · 1 revision

The folder 'Attack case' contains logs generated by Zeek-Agent from an attack. You can upload the data to elasticsearch using 'es_load.py'. The compromised file is 'syslog' which you can search on and trace the attack, you might observe a note from the attacker when clicking on one of the process nodes. The note will be present in the 'message.txt' file. The freeze exploration command will prove to be helpful to see node details without exploring them.

Clone this wiki locally