
: 005 zeektest CHANTYPES=# EXCEPTS INVEX CHANMODES=eIbq,k,flj,CFLMPQScgimnprstuz CHANLIMIT=#:120 MAXLIST=bqeI:100 MODES=4 NETWORK=freenode CALLERID=g CASEMAPPING=rfc1459 :are supported by this server : 004 zeektest ircd-seven-1.1.9 DOQRSZaghilopsuwz CFILMPQSbcefgijklmnopqrstuvz bkloveqjfI : 003 zeektest :This server was created Thu at 20:10:02 UTC : 002 zeektest :Your host is, running version ircd-seven-1.1.9

: 001 zeektest :Welcome to the freenode Internet Relay Chat Network zeektest : CAP * LS :account-notify away-notify cap-notify chghost extended-join identify-msg multi-prefix sasl tlsĬAP REQ :account-notify away-notify cap-notify chghost extended-join identify-msg multi-prefix : CAP zeektest ACK :account-notify away-notify cap-notify chghost extended-join identify-msg multi-prefix CAP END NICK zeektest USER zeektest 0 * :realname : NOTICE * :*** Looking up your hostname. I have edited the transcript to focus on essential items. Useful to see the contents of an IRC session. Reconstructing an IRC Session ¶īefore examining the data provided by Zeek’s irc.log, it might be However, for both unencrypted or encrypted sessions, IRCįor full details on each field in the irc.log file, please see Implementations of IRC servers offer IRC over TLS, with the servers listening Making it possible for an analyst to manually inspect them. The commands and responses are text-based, Traditionally, IRC clients connect via a clear-text TCP session to an IRC Issue instructions to clients that controlled compromised systems. Second, IRC enabled command-and-control, thanks to the ability for operators to It may not have been suspicious or malicious to see IRC traffic on the wire. Some intruders eventually began using IRC toĬontrol botnets, primarily for two reasons. The Zeek project hosted an IRC channel for many years to supportĭevelopment and discussion.

Internet Relay Chat (IRC) is an older protocol that enables real time chat andĬollaboration.
