I am new to zeek/bro\. For an internship which will complete a master course I have been attending, I will work with zeek and specifically with the CIFS/SMB analyzer\. After looking at the documentation and the code, it seems to me that the this analyzer \(as available in zeek github master branch\) was written in BinPac language and only the most used protocol commands are implemented\. I could possibly work on extending the current implementation of the protocol\.
Do you have any thoughts/suggestions about this? Is anyone already doing (or planning to do) it?