Comments (3)
i think the problem might be zeek
from tinycheck.
Running into the same problem. It seems like the log file format of zeek has changed. The offending python code is checking trying to find tx_hosts
in /tmp/<id>/assets/files.log
, but that string isn't in there.
from tinycheck.
I changed lines 272 and 274 in /usr/share/tinycheck/analysis/classes/zeekengine.py
like this:
c = {"ip_dst": record["id.resp_h"],
...
"port_dst": record["id.resp_p"],
Then I was able to run the analysis manually by calling sudo python3 /usr/share/tinycheck/analysis/analysis.py /tmp/<id>/
and found results in alerts.json.
I'll create a PR tomorrow.
EDIT: Fixed typo in code
from tinycheck.
Related Issues (20)
- Raspberry Pi OS (64-bit) HOT 2
- IOCs detection issue ? HOT 3
- analysis.py need pango-1.0-0 HOT 1
- Pdf Report errors in the font HOT 1
- The device is not recognized HOT 1
- Analysis runs for hours with no results
- flask dependency on Raspbian 10, very old version of werkzeug
- Installation stuck HOT 2
- Installation instructions in wiki are outdated HOT 4
- Installation instructions in wiki do not reflect 32 bit normal or full Raspbian is needed HOT 2
- Unable to access the network HOT 2
- Issue with the convert_unicode argument on SQLAlchemy HOT 9
- Error on Driver Installation - need help
- 127.0.0.1 refused to connect HOT 11
- Install: "You must select two interfaces, exiting" HOT 4
- Getting expired key warning for Zeek packages when I try to update the system
- Bad password checks during install HOT 1
- How to connect and capture multiple devices HOT 2
- install.sh: Line 271: add-apt-repository: Command not found. HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from tinycheck.