# Writing a new analyzer

**URL:** <https://community.zeek.org/t/writing-a-new-analyzer/3047>\
**Category:** Zeek\
**Created:** [March 25, 2014, 5:37pm UTC](https://community.zeek.org/t/writing-a-new-analyzer/3047 "2014-03-25T17:37:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Thomas](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@Eric\_Thomas](https://community.zeek.org/u/Eric_Thomas)\
**Post date:** [March 25, 2014, 5:37pm UTC](https://community.zeek.org/t/writing-a-new-analyzer/3047/1 "2014-03-25T17:37:55Z")

</div>

Hello, I’d like to write a protocol analyzer, but I don’t know where to begin. Is BinPAC the recommended method? The documentation for BinPAC describes mostly types, so it’s not enough to get me started. I looked at some of the protocols that have .pac files and it’s way over my head at this stage. I found the BinPAC Sample Analyzer, which appears might be applicable mostly to Bro 1.X. Any other resources that could help?

---

<div class="post-metadata">

**Author:** ![Kyle\_Creyts](https://avatars.discourse-cdn.com/v4/letter/k/41988e/32.png) [@Kyle\_Creyts](https://community.zeek.org/u/Kyle_Creyts)\
**Post date:** [March 25, 2014, 5:56pm UTC](https://community.zeek.org/t/writing-a-new-analyzer/3047/2 "2014-03-25T17:56:30Z")

</div>

+1.

A tutorial/workshop on the subject would be very interesting to me.

---

<div class="post-metadata">

**Author:** ![Vlad\_Grigorescu2](https://avatars.discourse-cdn.com/v4/letter/v/c4cdca/32.png) [@Vlad\_Grigorescu2](https://community.zeek.org/u/Vlad_Grigorescu2)\
**Post date:** [March 25, 2014, 6:57pm UTC](https://community.zeek.org/t/writing-a-new-analyzer/3047/3 "2014-03-25T18:57:49Z")

</div>

Hi,

Please see: [http://www.bro.org/development/howtos/binpac-sample-analyzer.html](http://www.bro.org/development/howtos/binpac-sample-analyzer.html) and the presentation I gave on this at the last Bro Exchange: [https://www.youtube.com/watch?v=l44MqU0l6M8&feature=youtu.be](https://www.youtube.com/watch?v=l44MqU0l6M8&feature=youtu.be) My binpac-quickstart script is at: [https://github.com/grigorescu/binpac\_quickstart](https://github.com/grigorescu/binpac_quickstart)

If you have any specific questions, throw them out to this list and we'll see if we can help.

&nbsp;&nbsp;--Vlad

---

<div class="post-metadata">

**Author:** ![Eric\_Thomas](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@Eric\_Thomas](https://community.zeek.org/u/Eric_Thomas)\
**Post date:** [March 25, 2014, 10:30pm UTC](https://community.zeek.org/t/writing-a-new-analyzer/3047/4 "2014-03-25T22:30:20Z")

</div>

Already a big help, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/writing-a-new-analyzer/3047/5 "2022-05-06T15:41:40Z")

</div>


