- Lab
- Security

Detect and Analyze Network Threats with Zeek
Master the fundamentals of network threat detection using Zeek's powerful logging and analysis capabilities. You'll start by examining connection logs to identify anomalies, parse traffic data with zeek-cut, and uncover suspicious patterns in network behavior. From there, you'll investigate protocol mismatches, analyze missing data fields, and deploy custom detection scripts with correlation rules. The final analysis will demonstrate how to automatically detect multi-stage threats using Zeek's scripting framework, all while working with real-world network captures essential for SOC-level threat hunting.

Path Info
Table of Contents
-
Challenge
Analyze Connection Logs and Extract Insights
You'll analyze Zeek's connection logs to identify anomalies in network traffic. Also, you'll examine connection states, review connection history fields, and use zeek-cut to parse logs and extract critical insights about suspicious network behavior. By the end of this objective, you'll understand how to identify threats through log analysis.
-
Challenge
Detect Protocol Anomalies and Deploy Detection Scripts
Now that you've identified suspicious connection patterns, it's time to dig deeper into protocol-level anomalies. Attackers often exploit protocol mismatches or send malformed traffic to evade detection or exploit vulnerabilities. You'll investigate these anomalies and then deploy custom Zeek scripts to automatically detect similar threats in the future.
What's a lab?
Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.
Provided environment for hands-on practice
We will provide the credentials and environment necessary for you to practice right within your browser.
Guided walkthrough
Follow along with the author’s guided walkthrough and build something new in your provided environment!
Did you know?
On average, you retain 75% more of your learning if you get time for practice.