Skip to content
Discussion options

You must be logged in to vote

Most BZAR detections generate Zeek notices:
https://github.com/mitre-attack/bzar

So you might try to simulate some of the behavior listed at https://github.com/mitre-attack/bzar and then go to SOC Dashboards and select the Zeek Notice dashboard.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@oneCrazyAdmin
Comment options

@dougburks
Comment options

Answer selected by oneCrazyAdmin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants