From charlesreid1

Initial Notes

Intrusion detection system.

Bro training has pcaps with samples of things like malware hiding shells in HTTP traffic. For example:

Hat tip:


Debian - from source

To install on Debian from source, check out the repo with all submodules:

git clone --recursive

The INSTALL file is pretty clear with its instructions, but the summary:

sudo apt-get install cmake make gcc g++ flex bison libpcap-dev libssl-dev python-dev swig zlib1g-dev

In order to build Bro on Debian 9, install libssl1.0-dev instead of libssl-dev.


Then the usual:

sudo make install

this will install to /usr/local/bro


Before using, make sure you add /usr/local/bro/bin to your $PATH.

Allowing Non-Sudo Users to Capture Packets

To allow non-sudo users to capture packets:

sudo setcap cap_net_raw,cap_net_admin=eip /path/to/bro

You may also need to set permissions on the bro directory, depending on how it was installed.

Minimal Bro Configuration

The minimal starting configuration can be set by editing:

$PREFIX/etc/ to set the interface to monitor

$PREFIX/etc/networks.cfg to specify the networks to consider local

$PREFIX/etc/broctl.cfg to specify the email address and log rotation interval

$ cat /usr/local/bro/etc/node.cfg 
# Example BroControl node configuration.
# This example has a standalone node ready to go except for possibly changing
# the sniffing interface.

# This is a complete standalone configuration.  Most likely you will
# only need to change the interface.
$ cat /usr/local/bro/etc/networks.cfg 
# List of local networks in CIDR notation, optionally followed by a
# descriptive tag.
# For example, "" or "fe80::/64" are valid prefixes.

#          Private IP space         Private IP space       Private IP space      Private IP space
$ cat /usr/lcoal/bro/etc/broctl.cfg


LogRotationInterval = 86400



Start the BroControl shell:

$ broctl

If this is the first time using the shell, run the install command to install BroControl configuration:

[BroControl] > install


Bro documentation on github:

quickstart once you do make docs: file:///home/charles/codes/security/bro/build/html/quickstart/index.html