Skip to content

kyllr-qwen/Apricot

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Apricot Query Pack

Overview

The Apricot Query Pack provides a curated collection of ready-to-use Zed/Zui queries designed for analyzing Zeek, Suricata, and general network telemetry. This pack streamlines the process of examining network activity, detecting anomalies, and extracting meaningful insights from structured security data.

Features

  • Prebuilt query sets for Zeek and Suricata logs.
  • Standardized and optimized Zed queries.
  • Clean folder structure for use inside the Zui application.
  • Easy import process for rapid analysis.

Getting Started

1. Download the Repository

Clone the repository:

git clone https://github.com/tboy-hacker/apricot-queries.git

Or download the ZIP from the repository and extract it locally.

2. Import Into Zui

  1. Open the Zui application.
  2. Select + in the upper-left corner.
  3. Choose Import Queries….
  4. Select the JSON files from the Apricot folder.

After import, the queries will appear under the Queries panel in a folder named Apricot.

Usage

The pack includes queries for:

  • Network connection analysis
  • DNS activity and domain intelligence
  • HTTP traffic inspection
  • TLS certificate and handshake review
  • File activity and transfer tracing
  • Suricata alert investigation
  • General anomaly and behavior detection

Each query is categorized to make navigation simple inside Zui.

Contributing

Contributions are welcome. To contribute:

  1. Fork the repository.
  2. Create a feature branch.
  3. Add or update queries with proper documentation.
  4. Submit a pull request.

Support

For issues or questions, open an issue in the repository or contact: okwaratoto11@gmail.com

License

This project is licensed under the MIT License. See the LICENSE file for details.


If you want a more detailed version, a shorter one, or a version tailored specifically for Zeek-only or Suricata-only packs, I can refine it further.

About

Apricot Queries are helpful queries for getting started with analyzing data within the Zui app.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors