Virtual ZeekWeek 2020 is free to attend, but registration is required. 
Back To Schedule
Thursday, October 15 • 11:00am - 11:30am
Day 3 - Packaging Zeek's policy scripts with better zkg templating LIMITED

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.

Limited Capacity seats available

You MUST register through eventbrite to gain access to this session (Day 3)

Out of the box, Zeek comes with scripts for identifying malicious or suspicious traffic. These scripts are designed to be customizable to your environment, as "malicious" and "suspicious" are highly subjective. In this talk, we'll report on an emerging effort to migrate these to zkg packages. This provides a number of benefits, including faster iteration, a more community-driven feature set, explicit dependencies, and a more manageable codebase. To streamline this migration with consistent, maintainable, CI-enabled packages, we will also present a new open-source zkg package template authored by ESnet that lets script authors hit the ground running and avoid several potential pitfalls during package creation.

Slack Channel for this session -#vzw-day3-talk1-roadmap
Haven't joined the Zeek Slack space yet you can do so at:

Link to Session Survey - https://forms.gle/aFCTXniakuJGi7YN9 (this is part of the roadmap session number 15 on the survey)

avatar for Vlad Grigorescu

Vlad Grigorescu

Vlad Grigorescu has been working in information security since 2005, with a focus on open-source tool development, especially with Bro/Zeek. Most of this work has been in the academic and high-performance computing and networking space, as a security engineer at the University of... Read More →
avatar for Christian Kreibich

Christian Kreibich

Corelight, Inc.
Christian works at Corelight, where he's currently dedicating all his time to open-source Zeek. Prior to Corelight, he built and led the networking team at Lastline, served on the OISF advisory board, and was a staff researcher at the International Computer Science Institute. He holds... Read More →

Thursday October 15, 2020 11:00am - 11:30am PDT
Online - Zoom Meeting Room