performing-network-traffic-analysis-with-zeek

mukul975/performing-network-traffic-analysis-with-zeek · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.7 KB
  • 📁scripts
  • ⚙️agent.py 6.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. hunting-for-data-exfiltration-indicators · mukul975 bundle
    Analyze network traffic, logs, and data flows to detect potential data exfiltration via DNS tunneling, cloud storage uploads, encrypted channels, and other indicators of compromise.
    24.6k
    repo stars
  2. configuring-suricata-for-network-monitoring · mukul975 bundle
    Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms.
    24.6k
    repo stars
  3. detection-engineering-coverage-evaluation · google
    Automates detection engineering workflows in Google SecOps by extracting threat intelligence, generating detection opportunities, simulating attacker behavior with synthetic events, evaluating rule coverage, and creating new YARA-L 2.0 rules to close gaps.
    14.4k
    repo stars
  4. detecting-ransomware-precursors-in-network · mukul975 bundle
    Detects early-stage ransomware indicators in network traffic before encryption begins, using Zeek, Suricata, Arkime, SIEM correlation rules, and threat intelligence feeds to identify Cobalt Strike beacons, Mimikatz signatures, and RDP brute-force attempts.
    24.6k
    repo stars
  5. detecting-network-scanning-with-ids-signatures · mukul975 bundle
    Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.
    24.6k
    repo stars
  6. performing-network-traffic-analysis-with-tshark · mukul975 bundle
    Automates packet capture analysis using tshark and pyshark to extract protocol statistics, detect suspicious flows, identify IOCs, and analyze DNS anomalies from PCAP files.
    24.6k
    repo stars

Frequently asked questions

How do I install the performing-network-traffic-analysis-with-zeek skill?

Run npx skillmds add mukul975/performing-network-traffic-analysis-with-zeek in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-network-traffic-analysis-with-zeek skill do?

Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation. It is listed under Security, DevOps & Infra, Incident Response, Vulnerability Scanning on SkillMD.

Is performing-network-traffic-analysis-with-zeek safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-network-traffic-analysis-with-zeek?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-network-traffic-analysis-with-zeek free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-network-traffic-analysis-with-zeek?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.