Closed colder1989 closed 1 year ago
i think the problem might be zeek
Running into the same problem. It seems like the log file format of zeek has changed. The offending python code is checking trying to find tx_hosts
in /tmp/<id>/assets/files.log
, but that string isn't in there.
I changed lines 272 and 274 in /usr/share/tinycheck/analysis/classes/zeekengine.py
like this:
c = {"ip_dst": record["id.resp_h"],
...
"port_dst": record["id.resp_p"],
Then I was able to run the analysis manually by calling sudo python3 /usr/share/tinycheck/analysis/analysis.py /tmp/<id>/
and found results in alerts.json.
I'll create a PR tomorrow.
EDIT: Fixed typo in code
When i try to analyze the pcap i have this error in loop: