Sign inSign up

gravwell/zeek

By gravwell

•Updated over 1 year ago

ZEEK Network security scanner with preconfigured Gravwell File Follower

Image
3

1.9K

gravwell/zeek repository overview

⁠Overview

Refer to Gravwell's Docker⁠ guide for information on how to deploy ingester containers.

Note: The Zeek ingester requires a Linux host.

The zeek image is designed to be fed the listening interface and an optional BPF filter using environment variables. The listening interface is controlled using an environment variable named INTERFACE. If no INTERFACE environment variable is found, it defaults to listening on eth0. An optional BPF filter can be specified using the FILTER environment variable. The zeek log files are cleaned up every 15 minutes, with the Gravwell ingester handling the log retention.

⁠Running The Container

The Gravwell zeek log files are configured to be ingested using an integrated Gravwell File Follower. To configure the file follower, inject the appropriate indexer and ingest secret variables using either environment variables or docker secrets. See the docker ingester configuration⁠ section in the official Gravwell documentation for more information.

Here is an example docker run invocation.

The example will start a zeek container that is monitoring the host interface eno1 and ignoring all traffic on port 443. The Gravwell ingester is configured to send data to 2 indexers at 192.168.1.1 and 192.168.1.2 using the secret IngestSecrets.

docker run -d --name zeek --net host \
    -e GRAVWELL_CLEARTEXT_TARGETS="192.168.1.1,192.168.1.2" \
    -e GRAVWELL_INGEST_SECRET="IngestSecrets" \
    -e INTERFACE="eno1" \
    -e FILTER="not port 443" \
    gravwell/zeek:latest

Also checkout the Zeek kit⁠ for ready-to-roll Zeek analytics and content.

⁠Running With a Custom Plugin List

By default the container starts using a main.zeek located at /main.zeek (see below for the default plugin/configuration). If you would like to run with a custom configuration use a volume mount to override the main.zeek configuration file:

docker run -d --name zeek --net host -v /path/to/main.zeek:/main.zeek \
    -e GRAVWELL_CLEARTEXT_TARGETS="192.168.1.1,192.168.1.2" \
    -e GRAVWELL_INGEST_SECRET="IngestSecrets" \
    -e INTERFACE="eno1" \
    -e FILTER="not port 443" \
    gravwell/zeek:latest

NOTE: It is critical that you provide an unlink rotation processor at the top of your configuration file. If you do not provide a rotation processor the Zeek container will not unlink/remove old logs and your container will just grow and grow until you run out of space. Here is the unlink function in the default main.zeek.

function unlink_rotation_postprocessor_func(info: Log::RotationInfo) : bool
{
	#print_raw("deleting  ", info$fname, "\n");
	unlink(info$fname);
	return T;
}

⁠Zeek Information

The container is built using the open source Zeek distribution available on Github⁠.

Also included are a few ICS specific 3rd party plugins:

⁠Versions

Zeek Version: 3.2.3

Gravwell File Follow Version: 4.1.3

⁠Default Zeek Main Configuration
# Simple function that just blows away logs rather than rotate them
function unlink_rotation_postprocessor_func(info: Log::RotationInfo) : bool
	{
	#print_raw("deleting  ", info$fname, "\n");
	unlink(info$fname);
	return T;
	}

#assign our log rotation function as the only post processor
redef Log::default_rotation_postprocessors = { [Log::WRITER_ASCII] = unlink_rotation_postprocessor_func };

#set log rotation to a pretty fast rate
redef Log::default_rotation_interval = 600 secs;

#load some additional items, much of this is taken straight out of local.zeek script
# Apply the default tuning scripts for common tuning settings.
@load tuning/defaults

# Estimate and log capture loss.
@load misc/capture-loss

# Enable logging of memory, packet and lag statistics.
@load misc/stats

# Load the scan detection script.  It's disabled by default because
# it often causes performance issues.
#@load misc/scan

# Detect traceroute being run on the network. This could possibly cause
# performance trouble when there are a lot of traceroutes on your network.
# Enable cautiously.
#@load misc/detect-traceroute

# Generate notices when vulnerable versions of software are discovered.
# The default is to only monitor software found in the address space defined
# as "local".  Refer to the software framework's documentation for more
# information.
@load frameworks/software/vulnerable

# Detect software changing (e.g. attacker installing hacked SSHD).
@load frameworks/software/version-changes

# This adds signatures to detect cleartext forward and reverse windows shells.
@load-sigs frameworks/signatures/detect-windows-shells

# Load all of the scripts that detect software in various protocols.
@load protocols/ftp/software
@load protocols/smtp/software
@load protocols/ssh/software
@load protocols/http/software
# The detect-webapps script could possibly cause performance trouble when
# running on live traffic.  Enable it cautiously.
#@load protocols/http/detect-webapps

# This script detects DNS results pointing toward your Site::local_nets
# where the name is not part of your local DNS zone and is being hosted
# externally.  Requires that the Site::local_zones variable is defined.
@load protocols/dns/detect-external-names

# Script to detect various activity in FTP sessions.
@load protocols/ftp/detect

# Scripts that do asset tracking.
@load protocols/conn/known-hosts
@load protocols/conn/known-services
@load protocols/ssl/known-certs

# This script enables SSL/TLS certificate validation.
@load protocols/ssl/validate-certs

# This script prevents the logging of SSL CA certificates in x509.log
@load protocols/ssl/log-hostcerts-only

# Uncomment the following line to check each SSL certificate hash against the ICSI
# certificate notary service; see http://notary.icsi.berkeley.edu .
# @load protocols/ssl/notary

# If you have GeoIP support built in, do some geographic detections and
# logging for SSH traffic.
@load protocols/ssh/geo-data
# Detect hosts doing SSH bruteforce attacks.
@load protocols/ssh/detect-bruteforcing
# Detect logins using "interesting" hostnames.
@load protocols/ssh/interesting-hostnames

# Detect SQL injection attacks.
@load protocols/http/detect-sqli

#### Network File Handling ####

# Enable MD5 and SHA1 hashing for all files.
@load frameworks/files/hash-all-files

# Detect SHA1 sums in Team Cymru's Malware Hash Registry.
@load frameworks/files/detect-MHR

# Extend email alerting to include hostnames
#@load policy/frameworks/notice/extend-email/hostnames

# Uncomment the following line to enable detection of the heartbleed attack. Enabling
# this might impact performance a bit.
# @load policy/protocols/ssl/heartbleed

# Uncomment the following line to enable logging of connection VLANs. Enabling
# this adds two VLAN fields to the conn.log file.
# @load policy/protocols/conn/vlan-logging

# Uncomment the following line to enable logging of link-layer addresses. Enabling
# this adds the link-layer address for each connection endpoint to the conn.log file.
# @load policy/protocols/conn/mac-logging
#
#Load the asset tracket system
@load policy/tuning/track-all-assets


# OT related plugins - 
#Load the cisagov plugins
@load icsnpp-dnp3
@load icsnpp-modbus

Tag summary

Content type

Image

Digest

sha256:2083eac49…

Size

161.5 MB

Last updated

over 1 year ago

docker pull gravwell/zeek