zeek/doc/traces
Tim Wojtulewicz ded98cd373 Copy docs into Zeek repo directly
This is based on commit 2731def9159247e6da8a3191783c89683363689c from the
zeek-docs repo.
2025-09-26 02:58:29 +00:00
..
20171220_smb_at_schedule.pcap Copy docs into Zeek repo directly 2025-09-26 02:58:29 +00:00
get.trace Copy docs into Zeek repo directly 2025-09-26 02:58:29 +00:00
quickstart.pcap Copy docs into Zeek repo directly 2025-09-26 02:58:29 +00:00
README Copy docs into Zeek repo directly 2025-09-26 02:58:29 +00:00

Traces used in the examples of the docs.

* tm1t.pcap

  ?

* 20171220_smb_at_schedule.pcap

  References:

  https://redmine.openinfosecfoundation.org/issues/3109
  https://github.com/tianyulab/Hunting_lateral_movement/blob/master/20171220_smb_at_schedule.pcap

  SHA1:

  b5c5329536c7add1267cbbc50ac1436387c0b773

* get.trace

  That's the zeek/testing/btest/Traces/http/get.trace one.

* quickstart.pcap

  From curl commands:

  curl -X GET http://zeek.org
  curl -X WEIRD http://zeek.org