BZAR
A set of Bro/Zeek scripts that detect ATT&CK-based adversarial activity and raise notices

BZAR
A set of Bro/Zeek scripts that detect ATT&CK-based adversarial activity and raise notices
BZAR Description
BZAR (Bro/Zeek ATT&CK-based Analytics and Reporting) is a set of Bro/Zeek scripts that utilize the SMB and DCE-RPC protocol analyzers and the File Extraction Framework to detect ATT&CK-like activity, raise notices, and write to the Notice Log. It uses the Bro/Zeek Network Security Monitor to detect ATT&CK-based adversarial activity and is a component of the Cyber Analytics Repository. BZAR must be tuned for your specific operational environment to avoid unnecessary entries in the Notice Log.
BZAR FAQ
Common questions about BZAR including features, pricing, alternatives, and user reviews.
BZAR is A set of Bro/Zeek scripts that detect ATT&CK-based adversarial activity and raise notices. It is a Network Security solution designed to help security teams with MITRE Attack.