# Clarification on Backdoor Event Engine

**URL:** <https://community.zeek.org/t/clarification-on-backdoor-event-engine/992>\
**Category:** Zeek\
**Created:** [July 6, 2006, 6:14pm UTC](https://community.zeek.org/t/clarification-on-backdoor-event-engine/992 "2006-07-06T18:14:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anandraj](https://avatars.discourse-cdn.com/v4/letter/a/6a8cbe/32.png) [@Anandraj](https://community.zeek.org/u/Anandraj)\
**Post date:** [July 6, 2006, 6:14pm UTC](https://community.zeek.org/t/clarification-on-backdoor-event-engine/992/1 "2006-07-06T18:14:54Z")

</div>

Hi all,  
I just wanna clarify that , is the backdoor event engine(which does all  
&nbsp;&nbsp;&nbsp;&nbsp;the signature detection) eventually invokes the corresponding event  
&nbsp;&nbsp;&nbsp;&nbsp;engine and the Analyser .

&nbsp;&nbsp;&nbsp;&nbsp;For example let me take SSH , when the ssh packet is recevied  
&nbsp;&nbsp;&nbsp;&nbsp;through  
&nbsp;&nbsp;&nbsp;&nbsp;the libpcap , the backdoor event engine will be th e one which  
&nbsp;&nbsp;&nbsp;&nbsp;handles  
&nbsp;&nbsp;&nbsp;&nbsp;the packet first , based on the signatures invokes the ssh event  
&nbsp;&nbsp;&nbsp;&nbsp;engine  
&nbsp;&nbsp;&nbsp;&nbsp;and the ssh event engine invokes the Policy scripts which contain  
&nbsp;&nbsp;&nbsp;&nbsp;the  
&nbsp;&nbsp;&nbsp;&nbsp;event handlers/analysers ..finally log the data to the file.

&nbsp;&nbsp;&nbsp;&nbsp;Please correct me if my understanding is wrong.

&nbsp;&nbsp;&nbsp;&nbsp;Thanks,  
&nbsp;&nbsp;&nbsp;&nbsp;Anand

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/clarification-on-backdoor-event-engine/992/2 "2022-05-06T15:37:54Z")

</div>


