-
Notifications
You must be signed in to change notification settings - Fork 518
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
FEATURE: Zeek QUIC #6925
Comments
At a https://github.com/corelight/zeek-quic may be more current. |
Punny! 😂 |
Are there any plans to implement this? |
I think the latest Zeek version it supports is 4.1. If the author updates it to support Zeek 6 then we can consider it. |
Looks like they are planning on putting it into core. |
QUIC v1 INITIAL packet parsing now included in Zeek v6.1, handling of v2 INITIAL packets added in v6.2. Securityonion v2.4.70 includes Zeek v6.0.4. |
Just curious to learn more about this work. I'm interested in tracking things like Encrypted Client Hello (ECH) handshakes and QUIC connections. |
Hi @boblord our upcoming version 2.4.120 includes Zeek 7 and I can confirm that it is analyzing QUIC connections and writing out a quic.log. As time allows, we'll look into ingesting that log into Elasticsearch. |
Here's the PR for ingesting and parsing quic.log, a new QUIC dashboard, a new QUIC query for Hunt, and custom columns for QUIC events: |
Discussed in #6916
Originally posted by petiepooo January 18, 2022
More and more, we're seeing QUIC traffic. It would be nice to integrate https://github.com/salesforce/GQUIC_Protocol_Analyzer into zeek in SecurityOnion.
The text was updated successfully, but these errors were encountered: