zeek/doc/traces/README
Tim Wojtulewicz ded98cd373 Copy docs into Zeek repo directly
This is based on commit 2731def9159247e6da8a3191783c89683363689c from the
zeek-docs repo.
2025-09-26 02:58:29 +00:00

27 lines
493 B
Text

Traces used in the examples of the docs.
* tm1t.pcap
?
* 20171220_smb_at_schedule.pcap
References:
https://redmine.openinfosecfoundation.org/issues/3109
https://github.com/tianyulab/Hunting_lateral_movement/blob/master/20171220_smb_at_schedule.pcap
SHA1:
b5c5329536c7add1267cbbc50ac1436387c0b773
* get.trace
That's the zeek/testing/btest/Traces/http/get.trace one.
* quickstart.pcap
From curl commands:
curl -X GET http://zeek.org
curl -X WEIRD http://zeek.org