Agent skill

Performing Network Traffic Analysis With Zeek

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…

Apache-2.0Auto-check: notesSecurity

Install Performing Network Traffic Analysis With Zeek

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-network-traffic-analysis-with-zeek -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-network-traffic-analysis-with-zeek --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-network-traffic-analysis-with-zeek .claude/skills/performing-network-traffic-analysis-with-zeek && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-network-traffic-analysis-with-zeek
GitHub stars
34k
Token cost
~3.2k tokens
SKILL.md length
527 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…

  • Works in 6 steps: Install and Configure Zeek → Configure Logging and Output → Write Custom Detection Scripts → …
  • Standing up continuous
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 4 more sections
  • Runs Python scripts from its folder; calls apt-get; reaches download.opensuse.org

What it does

Performing Network Traffic Analysis With Zeek is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and integrate outputs with SIEM platforms. Use when standing up continuous, high-fidelity network traffic monitoring for threat detection, anomaly identification, or forensic investigation beyond what raw PCAP analysis provides.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Security operations, Transactional email and Network security. It works with Wireshark. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Standing up continuous
  • High-fidelity network traffic monitoring for threat detection
  • Anomaly identification
  • Forensic investigation beyond what raw PCAP analysis provides

Example prompts

  • “/performing-network-traffic-analysis-with-zeek”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Install and Configure Zeek
  2. Configure Logging and Output
  3. Write Custom Detection Scripts
  4. Configure Intel Framework
  5. Deploy and Operate
  6. SIEM Integration

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • download.opensuse.org

    Also links to:

    • docs.zeek.org
    • cisa.gov
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Network Traffic Analysis With Zeek loads about 3.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 527 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:95
    sudo apt-get install -y zeek
  • NoteRuns commands with sudoSKILL.md:99
    sudo tee /etc/apt/sources.list.d/zeek.list
  • NoteRuns commands with sudoSKILL.md:100
    sudo apt-get update && sudo apt-get install -y zeek-lts
  • NoteRuns commands with sudoSKILL.md:336
    sudo /opt/zeek/bin/zeekctl deploy
  • NoteRuns commands with sudoSKILL.md:339
    sudo /opt/zeek/bin/zeekctl status
  • NoteRuns commands with sudoSKILL.md:351
    sudo /opt/zeek/bin/zeekctl cron

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 527 words, ~3,174 tokens.

Download SKILL.mdSave it as .claude/skills/performing-network-traffic-analysis-with-zeek/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-network-traffic-analysis-with-zeek
description
Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and integrate outputs with SIEM platforms. Use when standing up continuous, high-fidelity network traffic monitoring for threat detection, anomaly identification, or forensic investigation beyond what raw PCAP analysis provides.
domain
cybersecurity
subdomain
network-security
tags
zeek, network-monitoring, traffic-analysis, ids, nids, pcap, threat-detection, forensics, siem-integration
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03, PR.DS-02
mitre_attack
T1046, T1040, T1557, T1071, T1685.002

Performing Network Traffic Analysis with Zeek

Overview

Zeek (formerly Bro) is an open-source network analysis framework that operates as a passive network security monitor. Unlike traditional signature-based IDS tools, Zeek generates high-fidelity structured logs from observed network traffic, capturing detailed metadata for protocols including HTTP, DNS, TLS, SSH, SMTP, FTP, and dozens more. Zeek's extensible scripting language enables custom detection logic, behavioral analysis, and automated response. This skill covers deploying Zeek, understanding its log architecture, writing custom detection scripts, and integrating outputs with SIEM platforms.

When to Use

  • When conducting security assessments that involve performing network traffic analysis with zeek
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Linux server (Ubuntu 22.04+ or CentOS 8+) with 4+ CPU cores and 8GB+ RAM
  • Network TAP or SPAN port mirroring configured for traffic capture
  • Zeek 6.0+ installed (via package manager or source compilation)
  • Root or capture group privileges for packet capture
  • SIEM platform (Splunk, ELK Stack, or QRadar) for log ingestion

Core Concepts

Zeek Architecture

Zeek operates in two main modes:

  1. Live Capture - Monitors traffic in real-time on one or more network interfaces
  2. Offline Analysis - Processes saved PCAP files for retrospective analysis

The processing pipeline consists of:

  • Packet Capture Layer - Reads raw packets from interfaces or PCAP files
  • Event Engine - Reassembles TCP streams and generates protocol events
  • Script Interpreter - Executes Zeek scripts that process events and generate logs
  • Log Framework - Writes structured logs in TSV, JSON, or custom formats
Log Architecture

Zeek generates protocol-specific log files:

Log FileDescription
conn.logTCP/UDP/ICMP connection summaries with duration, bytes, state
dns.logDNS queries and responses with query type, answers, TTL
http.logHTTP requests/responses with URIs, user agents, MIME types
ssl.logTLS handshake details including certificate chain, JA3/JA3S
files.logFile transfers with MIME types, hashes (MD5, SHA1, SHA256)
notice.logAlerts generated by Zeek detection scripts
weird.logProtocol anomalies and unexpected behaviors
x509.logCertificate details from TLS connections
smtp.logEmail metadata including sender, recipient, subject
ssh.logSSH connection details and authentication results
pe.logPortable Executable file metadata
dpd.logDynamic Protocol Detection failures
Show full SKILL.md (173 more words)Show less

Workflow

Step 1: Install and Configure Zeek
bash
# Install Zeek on Ubuntu
sudo apt-get install -y zeek

# Or install from Zeek repository
echo 'deb http://download.opensuse.org/repositories/security:/zeek/xUbuntu_22.04/ /' | \
    sudo tee /etc/apt/sources.list.d/zeek.list
sudo apt-get update && sudo apt-get install -y zeek-lts

# Verify installation
zeek --version

Configure the node layout in /opt/zeek/etc/node.cfg:

ini
[manager]
type=manager
host=localhost

[proxy-1]
type=proxy
host=localhost

[worker-1]
type=worker
host=localhost
interface=eth0
lb_method=pf_ring
lb_procs=4

[worker-2]
type=worker
host=localhost
interface=eth1
lb_method=pf_ring
lb_procs=4

Configure network definitions in /opt/zeek/etc/networks.cfg:

# Internal network ranges
10.0.0.0/8         Private RFC1918
172.16.0.0/12      Private RFC1918
192.168.0.0/16     Private RFC1918
Step 2: Configure Logging and Output

Edit /opt/zeek/share/zeek/site/local.zeek:

zeek
# Load standard detection scripts
@load base/protocols/conn
@load base/protocols/dns
@load base/protocols/http
@load base/protocols/ssl
@load base/protocols/ssh
@load base/protocols/smtp
@load base/protocols/ftp

# Load file analysis
@load base/files/hash-all-files
@load base/files/extract-all-files

# Load detection frameworks
@load base/frameworks/notice
@load base/frameworks/intel
@load base/frameworks/files
@load base/frameworks/software

# Load additional protocol analyzers
@load policy/protocols/ssl/validate-certs
@load policy/protocols/ssl/log-hostcerts-only
@load policy/protocols/ssh/detect-bruteforcing
@load policy/protocols/dns/detect-external-names
@load policy/protocols/http/detect-sqli

# Enable JA3 fingerprinting
@load policy/protocols/ssl/ja3

# Enable JSON output for SIEM ingestion
@load policy/tuning/json-logs

redef LogAscii::use_json = T;

# Configure file extraction directory
redef FileExtract::prefix = "/opt/zeek/extracted/";

# Set notice email
redef Notice::mail_dest = "soc@example.com";
Step 3: Write Custom Detection Scripts

Create detection scripts for common threats:

Detect DNS Tunneling (/opt/zeek/share/zeek/site/detect-dns-tunnel.zeek):

zeek
@load base/protocols/dns

module DNSTunnel;

export {
    redef enum Notice::Type += {
        DNS_Tunnel_Suspected
    };

    # Threshold for suspicious DNS query length
    const query_len_threshold = 50 &redef;

    # Track query counts per host per domain
    global dns_query_counts: table[addr, string] of count &default=0 &create_expire=5min;

    # High query volume threshold
    const query_volume_threshold = 100 &redef;
}

event dns_request(c: connection, msg: dns_msg, query: string, qtype: count, qclass: count)
{
    if ( |query| > query_len_threshold )
    {
        local parts = split_string(query, /\./);
        if ( |parts| > 3 )
        {
            local base_domain = cat(parts[|parts|-2], ".", parts[|parts|-1]);
            dns_query_counts[c$id$orig_h, base_domain] += 1;

            if ( dns_query_counts[c$id$orig_h, base_domain] > query_volume_threshold )
            {
                NOTICE([$note=DNS_Tunnel_Suspected,
                        $msg=fmt("Possible DNS tunneling: %s queries to %s with long query names",
                                 c$id$orig_h, base_domain),
                        $conn=c,
                        $identifier=cat(c$id$orig_h, base_domain),
                        $suppress_for=30min]);
            }
        }
    }
}

Detect Beaconing Behavior (/opt/zeek/share/zeek/site/detect-beaconing.zeek):

zeek
@load base/protocols/conn

module Beaconing;

export {
    redef enum Notice::Type += {
        C2_Beacon_Detected
    };

    # Track connection intervals
    global conn_intervals: table[addr, addr, port] of vector of time &create_expire=1hr;

    const min_connections = 20 &redef;
    const jitter_threshold = 0.15 &redef;
}

event connection_state_remove(c: connection)
{
    if ( c$id$resp_p == 80/tcp || c$id$resp_p == 443/tcp )
    {
        local key = [c$id$orig_h, c$id$resp_h, c$id$resp_p];

        if ( key !in conn_intervals )
            conn_intervals[key] = vector();

        conn_intervals[key] += network_time();

        if ( |conn_intervals[key]| >= min_connections )
        {
            local intervals: vector of interval = vector();
            local i = 1;
            while ( i < |conn_intervals[key]| )
            {
                intervals += conn_intervals[key][i] - conn_intervals[key][i-1];
                i += 1;
            }

            # Calculate mean and standard deviation
            local sum_val = 0.0;
            for ( idx in intervals )
                sum_val += interval_to_double(intervals[idx]);

            local mean_val = sum_val / |intervals|;

            local variance = 0.0;
            for ( idx in intervals )
            {
                local diff = interval_to_double(intervals[idx]) - mean_val;
                variance += diff * diff;
            }
            variance = variance / |intervals|;
            local stddev = sqrt(variance);

            if ( mean_val > 0 && (stddev / mean_val) < jitter_threshold )
            {
                NOTICE([$note=C2_Beacon_Detected,
                        $msg=fmt("Possible C2 beaconing: %s -> %s:%s (interval=%.1fs, jitter=%.2f)",
                                 c$id$orig_h, c$id$resp_h, c$id$resp_p,
                                 mean_val, stddev/mean_val),
                        $conn=c,
                        $identifier=cat(c$id$orig_h, c$id$resp_h),
                        $suppress_for=1hr]);
            }
        }
    }
}
Step 4: Configure Intel Framework

Load threat intelligence feeds into Zeek:

zeek
# In local.zeek
@load frameworks/intel/seen
@load frameworks/intel/do_notice

redef Intel::read_files += {
    "/opt/zeek/intel/malicious-ips.intel",
    "/opt/zeek/intel/malicious-domains.intel",
    "/opt/zeek/intel/malicious-hashes.intel",
};

Intel file format (/opt/zeek/intel/malicious-ips.intel):

#fields	indicator	indicator_type	meta.source	meta.desc	meta.do_notice
198.51.100.50	Intel::ADDR	abuse.ch	Known C2 server	T
203.0.113.100	Intel::ADDR	threatfeed	Ransomware infrastructure	T
Step 5: Deploy and Operate
bash
# Deploy Zeek cluster
sudo /opt/zeek/bin/zeekctl deploy

# Check cluster status
sudo /opt/zeek/bin/zeekctl status

# Process offline PCAP
zeek -r capture.pcap local.zeek

# View logs
cat /opt/zeek/logs/current/conn.log | zeek-cut id.orig_h id.resp_h id.resp_p proto service duration orig_bytes resp_bytes

# Search for specific connections
cat /opt/zeek/logs/current/dns.log | zeek-cut query answers | grep -i "suspicious"

# Rotate logs
sudo /opt/zeek/bin/zeekctl cron
Step 6: SIEM Integration

Filebeat configuration for ELK Stack:

yaml
filebeat.inputs:
  - type: log
    enabled: true
    paths:
      - /opt/zeek/logs/current/*.log
    json.keys_under_root: true
    json.add_error_key: true
    fields:
      source: zeek
    fields_under_root: true

output.elasticsearch:
  hosts: ["https://elasticsearch:9200"]
  index: "zeek-%{+yyyy.MM.dd}"

setup.template.name: "zeek"
setup.template.pattern: "zeek-*"

Analysis Techniques

Connection Analysis
bash
# Find top talkers by bytes
cat conn.log | zeek-cut id.orig_h orig_bytes | sort -t$'\t' -k2 -rn | head -20

# Find long-duration connections (potential C2)
cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p duration | awk '$4 > 3600' | sort -t$'\t' -k4 -rn

# Find connections with unusual ports
cat conn.log | zeek-cut id.resp_p proto | sort | uniq -c | sort -rn | head -30
TLS Analysis
bash
# Find self-signed certificates
cat ssl.log | zeek-cut server_name validation_status | grep "self signed"

# Extract JA3 fingerprints for known malware
cat ssl.log | zeek-cut ja3 server_name | sort | uniq -c | sort -rn

# Find expired certificates
cat ssl.log | zeek-cut server_name not_valid_after | awk -F'\t' '$2 < systime()'

Best Practices

  • TAP Over SPAN - Use network TAPs instead of SPAN ports to avoid packet loss under load
  • Worker Scaling - Assign 1 Zeek worker per 1 Gbps of monitored traffic
  • AF_PACKET Clusters - Use AF_PACKET with load balancing for multi-core processing
  • Log Rotation - Configure automatic log rotation and archival (default: hourly)
  • Intel Updates - Automate threat intelligence feed updates at least daily
  • Packet Loss Monitoring - Monitor capture_loss.log for dropped packets
  • Custom Scripts - Develop organization-specific detections based on threat landscape

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-network-traffic-analysis-with-zeek of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Network Traffic Analysis With Zeek next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Network Traffic Analysis With Zeek compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Network Traffic Analysis With Zeek this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0
Traffic Analysis Pcapyaklang/hack-skills2.4k—~2.8kAutomated safety check: NotesMIT
TShark Traffic AnalysisAgentSecOps/SecOpsAgentKit2201 repos~4.8kAutomated safety check: NotesCustom licence
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Wireshark Analysiszebbern/claude-code-guide4.7k8 repos~3kAutomated safety check: PassMIT
IotnetBrownFineSecurity/iothackbot8591 repos~1kAutomated safety check: NotesMIT

Similar skills

  • Traffic Analysis Pcap

    yaklang/hack-skills

    Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~2.8k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • TShark Traffic Analysis

    AgentSecOps/SecOpsAgentKit

    Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

    220 GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Wireshark Analysis

    zebbern/claude-code-guide

    This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…

    4.7k GitHub starsUsed in 8 repos~3k tokens
    SecurityAuto-check passed
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    859 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Net

    zhinkgit/embeddedskills

    嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.

    734 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Performing Network Traffic Analysis With Zeek

What does Performing Network Traffic Analysis With Zeek do?

Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…. Performing Network Traffic Analysis With Zeek is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and integrate outputs with SIEM platforms.

When should I use Performing Network Traffic Analysis With Zeek?

Performing Network Traffic Analysis With Zeek fits situations like: standing up continuous; high-fidelity network traffic monitoring for threat detection; anomaly identification; forensic investigation beyond what raw PCAP analysis provides.

How do I install Performing Network Traffic Analysis With Zeek in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-network-traffic-analysis-with-zeek -a claude-code`. Or copy the skill folder (skills/performing-network-traffic-analysis-with-zeek in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-network-traffic-analysis-with-zeek in your project. Claude Code loads it when a task matches its description.

How do I install Performing Network Traffic Analysis With Zeek in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-network-traffic-analysis-with-zeek -a codex`. Or copy the skill folder (skills/performing-network-traffic-analysis-with-zeek in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-network-traffic-analysis-with-zeek in your project. Codex loads it when a task matches its description.

Can I use Performing Network Traffic Analysis With Zeek in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-network-traffic-analysis-with-zeek -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-network-traffic-analysis-with-zeek, .gemini/skills/performing-network-traffic-analysis-with-zeek, .github/skills/performing-network-traffic-analysis-with-zeek and .opencode/skills/performing-network-traffic-analysis-with-zeek in your project.

What does Performing Network Traffic Analysis With Zeek need to run?

Going by SKILL.md and its folder, Performing Network Traffic Analysis With Zeek needs Python for the scripts in its folder and the command-line tools its instructions call (apt-get). Our summary lists: Python 3.

Does Performing Network Traffic Analysis With Zeek access the network?

SKILL.md names 4 domains. In commands or code: download.opensuse.org; the agent is likely to contact it when it follows the instructions. As links in the text: docs.zeek.org, cisa.gov and github.com. This is read from the text; nothing was executed.

Is Performing Network Traffic Analysis With Zeek safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Network Traffic Analysis With Zeek use?

Performing Network Traffic Analysis With Zeek is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Network Traffic Analysis With Zeek use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 438 tokens, read only when the agent opens those files.

What are the alternatives to Performing Network Traffic Analysis With Zeek?

Skills that share tags, products or a category with Performing Network Traffic Analysis With Zeek: Traffic Analysis Pcap (yaklang/hack-skills, 2.4k stars), TShark Traffic Analysis (AgentSecOps/SecOpsAgentKit, 220 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars) and Wireshark Analysis (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Network Traffic Analysis With Zeek?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.