Featured When the fuzzers come knocking on port 389: Hunting injection canaries in LDAP Core protocols like LDAP are often left unmonitored. See how Zeek's ldap_search and DNS logs expose injection canaries and confirm whether attacks... Ben Reardon Sep 11, 2026
Zeek Pingback: ICMP Tunneling Malware This blog will introduce a method of detecting the Pingback malware in which attackers often hide their communications in ping message payloads. Corelight Labs Team May 7, 2021