# BZAR (Bro/Zeek ATT&CK-based Analytics and Reporting)

**URL:** <https://community.zeek.org/t/bzar-bro-zeek-att-ck-based-analytics-and-reporting/5976>\
**Category:** Zeek\
**Created:** [January 23, 2020, 10:32pm UTC](https://community.zeek.org/t/bzar-bro-zeek-att-ck-based-analytics-and-reporting/5976 "2020-01-23T22:32:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Francois\_Lachance](https://avatars.discourse-cdn.com/v4/letter/f/7c8e57/32.png) [@Francois\_Lachance](https://community.zeek.org/u/Francois_Lachance)\
**Post date:** [January 23, 2020, 10:32pm UTC](https://community.zeek.org/t/bzar-bro-zeek-att-ck-based-analytics-and-reporting/5976/1 "2020-01-23T22:32:02Z")

</div>

BZAR is a set of Bro/Zeek scripts utilizing the SMB and DCE-RPC protocol analyzers and the File Extraction Framework to detect ATT&CK-like activity, raise notices, and write to the Notice Log.

[https://github.com/mitre-attack/car/tree/master/implementations/bzar](https://github.com/mitre-attack/car/tree/master/implementations/bzar)

Has anyone tried this? Anyone have any feedback on these scripts?

I have Security Onion in my environment and I am considering trying this. I just don’t know where to start when it comes to installing and running custom scripts

Thanks!

**Francois**

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:47pm UTC](https://community.zeek.org/t/bzar-bro-zeek-att-ck-based-analytics-and-reporting/5976/2 "2022-05-06T15:47:00Z")

</div>


