Zeek Monthly Newsletter – Issue 4 – May 2020

Below is Issue 4 of the Zeek Monthly Newsletter. You can also find it at: https://zeek.org/2020/05/11/zeek-monthly-newsletter-issue-4-may-2020/

==Issue 4 - May 2020==

Welcome to the Zeek Monthly Newsletter, Issue 4 covers April 2020 as well as upcoming events.

===In this Issue:===

  • General Community News/Updates
  • Development Updates
  • Zeek in the News
  • Zeek In, Near and Around then Community
  • Interviews/Blog Posts
  • Threat of the Month
  • Upcoming Events
  • New Zeek Related Packages
  • Publication Schedule
  • Get Involved

===General Community News/Updates===

  • The Zeek Package Contest Is Still OPEN - ZPC-2 - The ZPC contest series is intended to inspire Zeek users to demonstrate their creativity and ingenuity while winning the admiration of their peers, and giving back to the community. The ZPC-2 contest will focus on the MITRE ATT&CK™ Framework, more specifically packages that help detect C2 Techniques. Find out more about how you can participate in ZPC-2 at: https://zeek.org/2020/04/06/zeek-package-contest-zpc-2/

  • Check out the Virtual Events this month!! - We have a full line up of events in May. Presentations for Zeek From Home include Looking Deeper into the Zeek 3.0 - Major Changes, Point Releases and more; Suricate and Security Onion. Ask the Zeeksperts will be hosted by Suricate and Brim and new for this month is a virtual Zeek community CTF (Capture the Flag) event. You can find out more about how to register for these events below in the events section.

===Development Updates===

===Zeek In, Near and Around The Community===

===Interviews/Blog Posts===

  • Zeek From Home – Episode 1 – Zeek-Agent – Recording Now Available - Zeek-Agent is an endpoint monitoring agent that provides host activity to Zeek. More information about Zeek-Agent can be found on the Zeek blog and Github

These webinars are recorded and if you were unable to attend the Zeek-Agent Zeek From Home episode we have made the following available: video, audio only and slides.
Many thanks to all those who participated!! Keep those questions and feedback coming!!
Find out more at: https://zeek.org/2020/04/17/zeek-from-home-episode-1-zeek-agent-recording-now-available/

===Threat of the Month===

Do you have a threat you’d like to share with the community and how using Zeek in your security stack helped you identify that threat? Please email news@zeek.org and we’ll work with you to get it written up and shared in the next newsletter.

===Upcoming Events===

The following is a list of Zeek Related online/virtual events for May 2020.

====Ask the Zeeksperts====

Ask the Zeeksperts is a one hour bi-weekly call that is hosted by various “Zeeksperts” in the community. This is where you can drop by and ask your Zeek Related questions. The webinars are free to attend, but registration is required.

====Zeek From Home====

This is a new weekly webinar series, where the community can share their Zeek Related presentations (scripts, use cases, how to’s, unique usages, lessons learned etc). These will be recorded.

====Capture the Flag Events====

These events are free but registration is required. See links below for more information.

  • 15 May 2020 4-6pm Eastern - Zeek Community CTF (Capture the Flag) - Players will compete head-to-head on dozens of security challenges using Zeek data in both Splunk and Elastic. Players can also use open-source Zeek tools on a CLI.
    Registration: https://www.eventbrite.com/e/zeek-community-ctf-capture-the-flag-tickets-10477636894

  • Corelight Virtual Hunt from Home (Every Tuesday and Thursday) - A free, 2-hour Virtual Capture the Flag event hosted by Corelight, where players compete to answer security challenges using Zeek data in Splunk and Elastic. The security challenges model realistic IR and hunting queries and can help you uplevel your Zeek log proficiency. Corelight experts will be on hand during the game to guide players of all skill levels through two exciting hunt scenarios. Sign up for one of eight virtual CTF spots in May. Game winners will take home bragging rights and a $100 Amazon Gift Card. https://www3.corelight.com/ctf/hunt-from-home

If you know of any Zeek related events that you would like to share with the community in the monthly newsletter, please email news@zeek.org or share on the Zeek mailing list (zeek@zeek.org).

====Zeek Related Packages/New Packages Added to packages.zeek.org====

====Publication Schedule (Updated)====

Issue 1 - January 2020 (Covers December 2019) - 14 January 2020 - https://zeek.org/2020/01/14/zeek-monthly-newsletter-issue-1-january-2020/
Issue 2 - March 2020 (Covers January and February 2020) - 2 March 2020 - https://zeek.org/2020/03/02/zeek-monthly-newsletter-issue-2-march-2020/
Issue 3 - April 2020 (Covers March 2020) - 7 April 2020 - https://zeek.org/2020/04/07/zeek-monthly-newsletter-issue-3-april-2020/
Issue 4 - May 2020 (Covers April 2020) - 8 May 2020 - https://zeek.org/2020/05/11/zeek-monthly-newsletter-issue-4-may-2020/
Issue 5 - June 2020 (Covers May 2020) - 1 June 2020
Issue 6 - July 2020 (Covers June 2020) - 6 July 2020
Issue 7 - August 2020 (Covers July 2020) - 3 August 2020
Issue 8 - September 2020 (Covers August 2020) - 7 September 2020
Issue 9 - October 2020 (Covers September 2020) - 5 October 2020
Issue 10 - November 2020 (Covers October 2020) - 2 November 2020
Issue 11 - December 2020 (Covers November 2020) - 7 December 2020
Issue 12 - Special Issue - (Year End Review) - 21 December 2020

====Get Involved====

If you are interested in getting involved with the Zeek Newsletter, please email news@zeek.org.

Join the News Slack Channel at: https://join.slack.com/t/zeekorg/shared_invite/enQtOTc3MzMxNDI1NDYxLTA1NzhhMTgxNWI1OTk2NjlkMTdjNzY1Nzk5NDk2ZDY1MDBkYWIxOWNjNDE2NDc2MGI5OWM3ZDllYzBmZmNhNDM

Follow us on Twitter at: https://twitter.com/Zeekurity