In this Zeek in Action video, Keith Jones explains his Spicy protocol analyzer rapid development process on a new Radius analyzer.  Of course Radius is in core Zeek, but it can be replaced with a Spicy Radius protocol analyzer.  Keith used this development process on the following open source Spicy analyzers:

In this detailed video, Keith explains his ten step process you can replicate:

  1. Install Zeek + Spicy + zkg
  2. Install Spicy plugin
  3. Create package with zkg create –template
  4. Find PCAPs
  5. Setup tests with PCAPs
  6. Find RFCs
  7. Write Spicy + Zeek code
  8. Push to GitHub
  9. Register package with
  10. Rejoice!

Slides used in this video can be found here.

If you would like to follow along, please check out our Zeek in Action playlist on the Zeek YouTube Channel.

If you would like to discuss the video, or consider creating one yourself, please visit the Zeek community Slack workspace and join the #documentation channel.

%d bloggers like this: