# Detection of packets with no TCP flags set

**URL:** <https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617>\
**Category:** Zeek\
**Created:** [February 28, 2019, 3:47am UTC](https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617 "2019-02-28T03:47:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![eshelton](https://avatars.discourse-cdn.com/v4/letter/e/c0e974/32.png) [@eshelton](https://community.zeek.org/u/eshelton)\
**Post date:** [February 28, 2019, 3:47am UTC](https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617/1 "2019-02-28T03:47:57Z")

</div>

Good evening,

My Google-fu is failing me right now, so I wanted to reach out to the list to see if anyone has ever attempted to use Zeek to detect packets with no TCP flags set?

In Snort land, a signature would look something like this:

alert tcp $HOME\_NET any → $EXTERNAL\_NET 443 (msg:“LOCAL Port 443 and no TCP flags set”; flags:0; classtype:misc-activity; sid:7;)

Before anyone asks, I’ll just ahead and state that “yes Virginia, these packets do really exist in the real world…” (though rare).

Thanks in advance,

-E

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [February 28, 2019, 4:43pm UTC](https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617/2 "2019-02-28T16:43:51Z")

</div>

I tried feeding Zeek two pcap files.

The first was a single TCP SYN packet with the flags nulled out. Zeek complained that the pcap only contained TCP control packets. The single entry in the conn.log file had a conn\_state of OTH.

The second was a single TLS connection over TCP. I nulled out the TCP flags of a single encrypted data packet (after the TCP and TLS handshakes had completed) and ran it through Zeek. Zeek processed the stream normally, with correct files, conn, x509, and ssl log entries, as if the packet I changed had the appropriate flags.

Could you say more about the null-flag packets you are referring to? Do you know what they are generated from?

-AK

---

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [February 28, 2019, 6:57pm UTC](https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617/3 "2019-02-28T18:57:18Z")

</div>

Zeek is mainly connection oriented, rather than packet oriented. However, you _could_ write a policy that allows for detection of these packets using the raw\_packet, new\_packet, or tcp packet events, bearing in mind the caveats in the documentation, particularly the expense of triggering events at the packet level.

If there is a particular concern about these packets (covert communication channel, perhaps?), it would be of interest.

Hope this helps,

Jim

---

<div class="post-metadata">

**Author:** ![Vlad\_Grigorescu](https://avatars.discourse-cdn.com/v4/letter/v/a3d4f5/32.png) [@Vlad\_Grigorescu](https://community.zeek.org/u/Vlad_Grigorescu)\
**Post date:** [March 4, 2019, 3:48pm UTC](https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617/4 "2019-03-04T15:48:12Z")

</div>

This seems like a job for Bro’s signature engine: [https://docs.zeek.org/en/stable/frameworks/signatures.html](https://docs.zeek.org/en/stable/frameworks/signatures.html)

Here’s an example: [http://try.bro.org/#/trybro/saved/303957](http://try.bro.org/#/trybro/saved/303957)

The signature I used is visible in the tcp.sig tab, copying it here for posterity:

> signature tcp-syn-no-flag {  
> ip-proto == tcp  
> header tcp[12:2] & 4095 == 2  
> event “Flag-less SYN”  
> }

Someone should double-check my logic there.

–Vlad

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [March 4, 2019, 6:17pm UTC](https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617/5 "2019-03-04T18:17:30Z")

</div>

I agree with Vlad. His response made me realize I only sent my response to Erin. Sending to the list for everyone’s benefit.

Try looking for conn.log lines with a conn$state of “OTH” and a conn$history value containing a ‘D’ or a ‘d’, indicating the connection carried data.

-AK

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/detection-of-packets-with-no-tcp-flags-set/5617/6 "2022-05-06T15:46:21Z")

</div>


