# Is it possible to inspect TCP reserved bits with Zeek?

**URL:** <https://community.zeek.org/t/is-it-possible-to-inspect-tcp-reserved-bits-with-zeek/6056>\
**Category:** Zeek\
**Created:** [March 23, 2020, 10:09pm UTC](https://community.zeek.org/t/is-it-possible-to-inspect-tcp-reserved-bits-with-zeek/6056 "2020-03-23T22:09:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tomek\_Koziak](https://avatars.discourse-cdn.com/v4/letter/t/b5ac83/32.png) [@Tomek\_Koziak](https://community.zeek.org/u/Tomek_Koziak)\
**Post date:** [March 23, 2020, 10:09pm UTC](https://community.zeek.org/t/is-it-possible-to-inspect-tcp-reserved-bits-with-zeek/6056/1 "2020-03-23T22:09:59Z")

</div>

Hi All,

I’m testing Zeek/Bro capabilities in terms of detecting different types of steganography. After working with the ICMP protocol now I am trying to inspect the TCP protocol. I want to detect if the reserved bits in TCP are changed with help of TCP events. Unfortunately without success.

Is it possible to inspect TCP reserved bits with Zeek events? If not is there any other possible way to detect wheter those bits where changed?

Best regards,  
Tomasz Koziak

---

<div class="post-metadata">

**Author:** ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Post date:** [March 24, 2020, 5:57pm UTC](https://community.zeek.org/t/is-it-possible-to-inspect-tcp-reserved-bits-with-zeek/6056/2 "2020-03-24T17:57:26Z")

</div>

I didn't see any events that currently carry the reserved bits, but it  
would be simple to extend existing ones like `new_packet` and  
`raw_packet`. You can find an example patch for that in the  
`topic/jsiwek/tcp-hdr-reserved-bits` branch here:

&nbsp;&nbsp;&nbsp;&nbsp;[https://github.com/zeek/zeek/compare/topic/jsiwek/tcp-hdr-reserved-bits](https://github.com/zeek/zeek/compare/topic/jsiwek/tcp-hdr-reserved-bits)

Let me know if that works for your purposes and I'll turn it into a  
pull request.

- Jon

---

<div class="post-metadata">

**Author:** ![Tomek\_Koziak](https://avatars.discourse-cdn.com/v4/letter/t/b5ac83/32.png) [@Tomek\_Koziak](https://community.zeek.org/u/Tomek_Koziak)\
**Post date:** [March 25, 2020, 9:53am UTC](https://community.zeek.org/t/is-it-possible-to-inspect-tcp-reserved-bits-with-zeek/6056/3 "2020-03-25T09:53:22Z")

</div>

Hi Jon.

Thank you, it’s working properly.  
In the first place, I have modified the TCP\_Flags.h to catch those bits, but your solution seems to be better.

Tomasz

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:47pm UTC](https://community.zeek.org/t/is-it-possible-to-inspect-tcp-reserved-bits-with-zeek/6056/4 "2022-05-06T15:47:09Z")

</div>


