zeek

Passive network traffic analyser.

TLDR

Analyze live traffic from a network interface

$ sudo zeek --iface [interface]
copy

Analyze live traffic from a network interface and load custom scripts

$ sudo zeek --iface [interface] [script1] [script2]
copy

Analyze live traffic from a network interface, without loading any scripts

$ sudo zeek --bare-mode --iface [interface]
copy

Analyze live traffic from a network interface, applying a tcpdump filter

$ sudo zeek --filter [path/to/filter] --iface [interface]
copy

Analyze live traffic from a network interface using a watchdog timer

$ sudo zeek --watchdog --iface [interface]
copy

Analyze traffic from a pcap file

$ zeek --readfile [path/to/file.trace]
copy

Copied to clipboard
sandbox