UPDATE: Bro/Zeek ATT&CK-based Analytics and Reporting (BZAR), by MITRE

Gary, All -

We updated the BZAR scripts to be forward-compatible with Zeek v2.6.x and backward-compatible with v2.5.x and below, using ‘@if’ directives to check the version number. Affected files include: main.bro, bzar_dce-rpc.bro, and bzar_smb.bro.

Please visit the GitHub repo to find the updates files.



Mark I. Fernandez

The MITRE Corporation


P.S. The Bro/Zeek Package Manager for BZAR is coming soon.