SIGNATURES
Last updated
Last updated
zeek supports signatures to find noteworthy activities on the network. zeek signatures use low-level pattern matching and cover conditions similar to Snort rules. unlike sort rules, zeek's rules which has a ".sig" extention are not the primary event detection point. zeek's scripting language can be used to chain multiple events to find an event of interest.