Zeek Blog

Bro Monthly #3

Bro Monthly #3 Welcome to the 3rd Bro Monthly newsletter. This month we cover the following topics: Bro Meet-ups: a new monthly category for Bro related gatherings and groups, Bro teaching and training, Bro in research, Bro in the wild, Bro-active: current exploits,...

read more

Bro Monthly #2

Bro Monthly #2Welcome to the 2nd Bro Monthly newsletter. This month we cover the followoing topics: Bro won a Bossie, Bro.org needs help, the Shellshock incident, new features in the Intel framework, news on BinPAC++, Bro in research, Bro in the wild, Bro on demand....

read more

Bro Monthly #1

Bro MonthlyWelcome to the 1st Bro Monthly, our new monthly newsletter covering the latest developments in the Bro universe. This newsletter will appear every month, around the 15th, as a Bro blog post. Please send feedback, wishes, and suggestions to info@bro.org or...

read more

Announcing Bro Live!

We are excited to announce the public release of Bro Live! Bro Live! is a training system that gives users hands-on access to a Bro learning environment without having to download a virtual machine or its required dependencies.  Bro Live! may be built with...

read more

Bro 2.3.1 Release

Bro v2.3.1 has been released.  This release addresses a potential DOS vector using specially crafted DNS packets.  It also fixes a bug in the OCSP validation code that could lead to crashes as well as a memory leak.  The source distribution and binary...

read more

Announcing Try.bro

We are very excited to announce the official launch of Try.bro.org! Try.bro is a web-based scripting sandbox made freely available to users on our site.  No login.  No installation.  No trouble. We have included a few basic scripts and pcaps to help get...

read more

Meet the Bro Teaching Community

We are happy to announce the newly started Bro Teaching Community, a community project of educators interested in collaboratively exploring Bro's use as a teaching tool, and sharing experiences and material. The goal is to create a knowledge base and resource...

read more

Bro 2.3 Release

We are happy to announce the release of Bro v2.3.  The source distribution and binary packages are available on our downloads page.  For a brief overview of new features and bug fixes you may review our previous blog post about the v2.3 beta....

read more

Bro 2.3 Public Beta

We are happy to announce the public beta of Bro v2.3 is available for download! The majority of our development time has been focused on improving performance, reliability, and memory use. Here is a brief summary of the new features and improvements: Support for GRE...

read more

Dissecting the GnuTLS Bug

Update: we now host a test server at gnutls.notary.icsi.berkeley.edu. See gnutls command lines below. The recent  GnuTLS certificate verification bug made it possible to craft an arbitrary certificate in a way that GnuTLS would validate correctly against a...

read more

Intelligence Data and Bro

Overview Intelligence data, or feeds, are an important source of network security information. Many internet security research centers, non-profit organizations, and commercial organizations provide intellegence data sets freely available to the public. (e.g. Emerging...

read more

Bro 2.2

Bro 2.2 has arrived. You can download the source distribution on our download page; binary packages will follow soon. For an overview of the major new features in 2.2, please see the earlier posting on the beta version. Since that beta, we have applied a range of...

read more

NSF Funds Bro Center of Expertise

We have some very exciting news to share today. The National Science Foundation (NSF) has awarded a new three-year grant to our team to establish a Bro Center of Expertise at ICSI and NCSA for supporting the NSF community in deploying Bro. The Center will provide the...

read more

Bro 2.2 Beta Available

It has been baking for a while, but now fresh out of the oven: we're happy to make a beta version of Bro 2.2 available on the download page for testing. Bro 2.2 comes with plenty new functionality, including a new file analysis framework for processing the content of...

read more

Meet Broala, LLC

Today we're delighted to introduce a new venture that we've been preparing in the background for a little while already: the International Computer Science Institute (ICSI) is spinning off a company, Broala, that provides professional Bro services to organizations...

read more

bro.org — A New Home for Bro

We are very excited to announce that as of today all Bro-related services have found a new home under the bro.org domain. We've moved most services over from bro-ids.org already, and the remaining pieces should fall in place over the next couple of days. Generally,...

read more

Watching for the APT1 Intelligence

Earlier this week, Mandiant released their APT1 report which I’m not going to bother providing any analysis or commentary on, there has been plenty of that this week. As a developer on a network analysis tool my interest primarily lies with consuming the...

read more

The Tree of Trust

As we mentioned in our preceding blog posting, ICSI has been harvesting details about SSL connections and their contained certificates since the beginning of this year.We use the data to provide a notary service to the community, which can be used to retrieve...

read more