ghcr.io/idaholab/malcolm/zeek:26.06.0 linux/amd64

ghcr.io/idaholab/malcolm/zeek:26.06.0 - 国内下载镜像源 浏览次数:9

ghcr.io/idaholab/malcolm/zeek是Malcolm项目中的Zeek组件镜像。Zeek(原称Bro)是一款开源的网络安全监控工具,可实时分析网络流量,生成详细的网络活动日志,支持检测异常流量、安全威胁等,是Malcolm网络流量分析平台的重要组成部分。

源镜像 ghcr.io/idaholab/malcolm/zeek:26.06.0
国内镜像 swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0
镜像ID sha256:1248de196bf6f34dde4755ccb3ad6b50a99a0dba9d4f60fe37b0207cb5213c5f
镜像TAG 26.06.0
大小 1.41GB
镜像源 ghcr.io
CMD /usr/local/bin/supervisord -c /etc/supervisord.conf -n
启动入口 /usr/bin/tini -- /usr/local/bin/docker-uid-gid-setup.sh /usr/local/bin/docker_entrypoint.sh /usr/local/bin/service_check_passthrough.sh -s zeek
工作目录
OS/平台 linux/amd64
浏览量 9 次
贡献者
镜像创建 2026-06-01T14:56:00.032245616Z
同步时间 2026-06-13 17:59
目录挂载
/usr/local/zeek/share/zeek/site/intel
环境变量
PATH=/usr/local/zeek/bin:/usr/local/zeek/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin PYTHONPATH=/usr/local/zeek/lib/zeek/python: DEBIAN_FRONTEND=noninteractive TERM=xterm PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 DEFAULT_UID=1000 DEFAULT_GID=1000 PUSER=zeeker PGROUP=zeeker PUSER_PRIV_DROP=false PUSER_RLIMIT_UNLOCK=true ZEEK_DIR=/usr/local/zeek CCACHE_DIR=/var/spool/ccache CCACHE_COMPRESS=1 SUPERCRONIC_VERSION=0.2.46 SUPERCRONIC_URL=https://github.com/aptible/supercronic/releases/download/v0.2.46/supercronic-linux- SUPERCRONIC_CRONTAB=/usr/local/zeek/etc/crontab ZEEK_THIRD_PARTY_PLUGINS_GREP=(Zeek::Spicy|ANALYZER_SPICY_OSPF|ANALYZER_SPICY_OPENVPN_UDP\b|ANALYZER_SPICY_IPSEC_UDP\b|ANALYZER_SPICY_TFTP|ANALYZER_SPICY_WIREGUARD|ANALYZER_C1222_UDP|ANALYZER_C1222_TCP|ANALYZER_SPICY_HART_IP_UDP|ANALYZER_SPICY_HART_IP_TCP|ANALYZER_ROC_PLUS_TCP|ANALYZER_ROC_PLUS_UDP|ANALYZER_OMRON_FINS_TCP|ANALYZER_OMRON_FINS_UDP|ANALYZER_SYNCHROPHASOR_TCP|ANALYZER_GENISYS_TCP|ANALYZER_SPICY_GE_SRTP|ANALYZER_SPICY_PROFINET_IO_CM|ANALYZER_S7COMM_TCP|Corelight::PE_XOR|ICSNPP::BACnet|ICSNPP::BSAP|ICSNPP::ENIP|ICSNPP::ETHERCAT|ICSNPP::OPCUA_Binary|Salesforce::GQUIC|Zeek::PROFINET|Zeek::TDS|Seiso::Kafka|JGras::FuzzyHashing) ZEEK_THIRD_PARTY_SCRIPTS_GREP=(bro-is-darknet/main|bro-simple-scan/scan|bzar/main|callstranger-detector/callstranger|cve-2020-0601/cve-2020-0601|cve-2020-13777/cve-2020-13777|CVE-2020-16898/CVE-2020-16898|CVE-2021-1675/main|CVE-2021-31166/detect|CVE-2021-38647/omigod|CVE-2021-41773/CVE_2021_41773|CVE-2021-42292/main|cve-2021-44228/CVE_2021_44228|cve-2022-21907/main|cve-2022-22954/main|CVE-2022-23270-PPTP/main|CVE-2022-24491/main|CVE-2022-24497/main|cve-2022-26809/main|CVE-2022-26937/main|CVE-2022-30216/main|CVE-2022-3602/__load__|hassh/hassh|http-more-files-names/main|ja4/main|pingback/detect|ripple20/ripple20|SIGRed/CVE-2020-1350|zeek-agenttesla-detector/main|zeek-asyncrat-detector/main|zeek-EternalSafety/main|zeek-httpattacks/main|zeek-netsupport-detector/main|zeek-quasarrat-detector/main|zeek-sniffpass/__load__|zeek-strrat-detector/main|zerologon/main|zeek-long-connections/main)\.(zeek|bro) AUTO_TAG=true ZEEK_PCAP_PROCESSOR=true ZEEK_INTEL_REFRESH_ON_STARTUP=false ZEEK_INTEL_REFRESH_ON_DEPLOY=false ZEEK_INTEL_REFRESH_CRON_EXPRESSION= ZEEK_AUTO_ANALYZE_PCAP_FILES=false ZEEK_AUTO_ANALYZE_PCAP_THREADS=1 ZEEK_INTEL_ITEM_EXPIRATION=-1min ZEEK_INTEL_REFRESH_THREADS=2 ZEEK_INTEL_FEED_SINCE= ZEEK_INTEL_FEED_SSL_CERTIFICATE_VERIFICATION=false ZEEK_EXTRACTOR_MODE=none ZEEK_EXTRACTOR_PATH=/zeek/extract_files ZEEK_INTEL_PATH=/usr/local/zeek/share/zeek/site/intel ZEEK_CUSTOM_PATH=/usr/local/zeek/share/zeek/site/custom ZEEK_UPLOAD_DIRECTORY=/zeek/upload PCAP_PROCESSED_DIRECTORY=/pcap/processed PCAP_PIPELINE_VERBOSITY= PCAP_MONITOR_HOST=pcap-monitor ZEEK_LIVE_CAPTURE=false ZEEK_ROTATED_PCAP=false PCAP_IFACE=lo PCAP_IFACE_TWEAK=false PCAP_FILTER= PCAP_NODE_NAME=malcolm ZEEK_DISABLE_STATS=true ZEEK_DISABLE_LOG_PASSWORDS= ZEEK_DISABLE_SSL_VALIDATE_CERTS= ZEEK_DISABLE_TRACK_ALL_ASSETS= ZEEK_DISABLE_DETECT_ROUTERS=true ZEEK_DISABLE_IANA_LOOKUP= ZEEK_DISABLE_BEST_GUESS_ICS=true ZEEK_DISABLE_SPICY_IPSEC= ZEEK_DISABLE_SPICY_LDAP= ZEEK_DISABLE_SPICY_OPENVPN= ZEEK_DISABLE_SPICY_QUIC=true ZEEK_DISABLE_SPICY_STUN= ZEEK_DISABLE_SPICY_TAILSCALE= ZEEK_DISABLE_SPICY_WIREGUARD= ZEEK_DISABLE_SPICY_ZIP=true ZEEK_C1222_AUTHENTICATION_VALUE=true ZEEK_C1222_IDENTIFICATION_SERVICE=true ZEEK_C1222_READ_WRITE_SERVICE=true ZEEK_C1222_LOGON_SECURITY_SERVICE=true ZEEK_C1222_WAIT_SERVICE=true ZEEK_C1222_DEREG_REG_SERVICE=true ZEEK_C1222_RESOLVE_SERVICE=true ZEEK_C1222_TRACE_SERVICE=true ZEEK_SYNCHROPHASOR_DETAILED= ZEEK_OMRON_FINS_DETAILED=true ZEEK_KAFKA_ENABLED= ZEEK_KAFKA_BROKERS=kafka.local:9091 ZEEK_KAFKA_TOPIC=zeek ZEEK_FILE_ANALYZER_TIMEOUT_SEC=5 PUSER_CHOWN=/usr/local/zeek/etc;/usr/local/zeek/share/zeek/site/custom;/usr/local/zeek/share/zeek/site/intel;/usr/local/zeek/share/zeekctl;/usr/local/zeek/spool BUILD_DATE=2026-06-01T14:15:01Z MALCOLM_VERSION=26.06.0 VCS_REVISION=0e21be1
镜像标签
malcolm@inl.gov: maintainer malcolm@inl.gov: org.opencontainers.image.authors 2026-06-01T14:15:01Z: org.opencontainers.image.created Malcolm container providing Zeek: org.opencontainers.image.description https://github.com/idaholab/Malcolm/blob/main/README.md: org.opencontainers.image.documentation BSD-3-Clause: org.opencontainers.image.licenses 0e21be1: org.opencontainers.image.revision https://github.com/idaholab/Malcolm: org.opencontainers.image.source ghcr.io/idaholab/malcolm/zeek: org.opencontainers.image.title https://github.com/idaholab/Malcolm: org.opencontainers.image.url Idaho National Laboratory: org.opencontainers.image.vendor 26.06.0: org.opencontainers.image.version
镜像安全扫描 查看Trivy扫描报告

系统OS: debian 13.4 扫描引擎: Trivy 扫描时间: 2026-06-13 17:59

低危漏洞:809 中危漏洞:533 高危漏洞:144 严重漏洞:16

Docker拉取命令

docker pull swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0
docker tag  swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0  ghcr.io/idaholab/malcolm/zeek:26.06.0

Containerd拉取命令

ctr images pull swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0
ctr images tag  swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0  ghcr.io/idaholab/malcolm/zeek:26.06.0

Shell快速替换命令

sed -i 's#ghcr.io/idaholab/malcolm/zeek:26.06.0#swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0#' deployment.yaml

Ansible快速分发-Docker

#ansible k8s -m shell -a 'docker pull swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0 && docker tag  swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0  ghcr.io/idaholab/malcolm/zeek:26.06.0'

Ansible快速分发-Containerd

#ansible k8s -m shell -a 'ctr images pull swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0 && ctr images tag  swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0  ghcr.io/idaholab/malcolm/zeek:26.06.0'

镜像构建历史


# 2026-06-01 22:56:00  0.00B 添加元数据标签
LABEL org.opencontainers.image.revision=0e21be1
                        
# 2026-06-01 22:56:00  0.00B 添加元数据标签
LABEL org.opencontainers.image.version=26.06.0
                        
# 2026-06-01 22:56:00  0.00B 添加元数据标签
LABEL org.opencontainers.image.created=2026-06-01T14:15:01Z
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 VCS_REVISION
ENV VCS_REVISION=0e21be1
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 MALCOLM_VERSION
ENV MALCOLM_VERSION=26.06.0
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 BUILD_DATE
ENV BUILD_DATE=2026-06-01T14:15:01Z
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG VCS_REVISION=0e21be1
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG MALCOLM_VERSION=26.06.0
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG BUILD_DATE=2026-06-01T14:15:01Z
                        
# 2026-06-01 22:56:00  0.00B 指定运行容器时使用的用户
USER root
                        
# 2026-06-01 22:56:00  0.00B 设置默认要执行的命令
CMD ["/usr/local/bin/supervisord" "-c" "/etc/supervisord.conf" "-n"]
                        
# 2026-06-01 22:56:00  0.00B 配置容器启动时运行的命令
ENTRYPOINT ["/usr/bin/tini" "--" "/usr/local/bin/docker-uid-gid-setup.sh" "/usr/local/bin/docker_entrypoint.sh" "/usr/local/bin/service_check_passthrough.sh" "-s" "zeek"]
                        
# 2026-06-01 22:56:00  0.00B 创建挂载点用于持久化数据或共享数据
VOLUME [/usr/local/zeek/share/zeek/site/intel]
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PUSER_CHOWN
ENV PUSER_CHOWN=/usr/local/zeek/etc;/usr/local/zeek/share/zeek/site/custom;/usr/local/zeek/share/zeek/site/intel;/usr/local/zeek/share/zeekctl;/usr/local/zeek/spool
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_FILE_ANALYZER_TIMEOUT_SEC
ENV ZEEK_FILE_ANALYZER_TIMEOUT_SEC=5
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_KAFKA_TOPIC
ENV ZEEK_KAFKA_TOPIC=zeek
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_KAFKA_BROKERS
ENV ZEEK_KAFKA_BROKERS=kafka.local:9091
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_KAFKA_ENABLED
ENV ZEEK_KAFKA_ENABLED=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_OMRON_FINS_DETAILED
ENV ZEEK_OMRON_FINS_DETAILED=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_SYNCHROPHASOR_DETAILED
ENV ZEEK_SYNCHROPHASOR_DETAILED=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_TRACE_SERVICE
ENV ZEEK_C1222_TRACE_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_RESOLVE_SERVICE
ENV ZEEK_C1222_RESOLVE_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_DEREG_REG_SERVICE
ENV ZEEK_C1222_DEREG_REG_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_WAIT_SERVICE
ENV ZEEK_C1222_WAIT_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_LOGON_SECURITY_SERVICE
ENV ZEEK_C1222_LOGON_SECURITY_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_READ_WRITE_SERVICE
ENV ZEEK_C1222_READ_WRITE_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_IDENTIFICATION_SERVICE
ENV ZEEK_C1222_IDENTIFICATION_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_C1222_AUTHENTICATION_VALUE
ENV ZEEK_C1222_AUTHENTICATION_VALUE=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_ZIP
ENV ZEEK_DISABLE_SPICY_ZIP=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_WIREGUARD
ENV ZEEK_DISABLE_SPICY_WIREGUARD=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_TAILSCALE
ENV ZEEK_DISABLE_SPICY_TAILSCALE=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_STUN
ENV ZEEK_DISABLE_SPICY_STUN=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_QUIC
ENV ZEEK_DISABLE_SPICY_QUIC=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_OPENVPN
ENV ZEEK_DISABLE_SPICY_OPENVPN=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_LDAP
ENV ZEEK_DISABLE_SPICY_LDAP=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SPICY_IPSEC
ENV ZEEK_DISABLE_SPICY_IPSEC=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_BEST_GUESS_ICS
ENV ZEEK_DISABLE_BEST_GUESS_ICS=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_IANA_LOOKUP
ENV ZEEK_DISABLE_IANA_LOOKUP=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_DETECT_ROUTERS
ENV ZEEK_DISABLE_DETECT_ROUTERS=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_TRACK_ALL_ASSETS
ENV ZEEK_DISABLE_TRACK_ALL_ASSETS=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_SSL_VALIDATE_CERTS
ENV ZEEK_DISABLE_SSL_VALIDATE_CERTS=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_LOG_PASSWORDS
ENV ZEEK_DISABLE_LOG_PASSWORDS=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_DISABLE_STATS
ENV ZEEK_DISABLE_STATS=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_FILE_ANALYZER_TIMEOUT_SEC=5
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_KAFKA_TOPIC=zeek
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_KAFKA_BROKERS=kafka.local:9091
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_KAFKA_ENABLED=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_OMRON_FINS_DETAILED=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_SYNCHROPHASOR_DETAILED=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_TRACE_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_RESOLVE_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_DEREG_REG_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_WAIT_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_LOGON_SECURITY_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_READ_WRITE_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_IDENTIFICATION_SERVICE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_C1222_AUTHENTICATION_VALUE=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_ZIP=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_WIREGUARD=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_TFTP=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_TAILSCALE=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_STUN=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_QUIC=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_OPENVPN=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_LDAP=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SPICY_IPSEC=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_BEST_GUESS_ICS=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_IANA_LOOKUP=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_DETECT_ROUTERS=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_TRACK_ALL_ASSETS=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_SSL_VALIDATE_CERTS=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_LOG_PASSWORDS=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_DISABLE_STATS=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PCAP_NODE_NAME
ENV PCAP_NODE_NAME=malcolm
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PCAP_FILTER
ENV PCAP_FILTER=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PCAP_IFACE_TWEAK
ENV PCAP_IFACE_TWEAK=false
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PCAP_IFACE
ENV PCAP_IFACE=lo
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_ROTATED_PCAP
ENV ZEEK_ROTATED_PCAP=false
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_LIVE_CAPTURE
ENV ZEEK_LIVE_CAPTURE=false
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PCAP_MONITOR_HOST
ENV PCAP_MONITOR_HOST=pcap-monitor
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PCAP_PIPELINE_VERBOSITY
ENV PCAP_PIPELINE_VERBOSITY=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 PCAP_PROCESSED_DIRECTORY
ENV PCAP_PROCESSED_DIRECTORY=/pcap/processed
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_UPLOAD_DIRECTORY
ENV ZEEK_UPLOAD_DIRECTORY=/zeek/upload
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_CUSTOM_PATH
ENV ZEEK_CUSTOM_PATH=/usr/local/zeek/share/zeek/site/custom
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_PATH
ENV ZEEK_INTEL_PATH=/usr/local/zeek/share/zeek/site/intel
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_EXTRACTOR_PATH
ENV ZEEK_EXTRACTOR_PATH=/zeek/extract_files
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_EXTRACTOR_MODE
ENV ZEEK_EXTRACTOR_MODE=none
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_FEED_SSL_CERTIFICATE_VERIFICATION
ENV ZEEK_INTEL_FEED_SSL_CERTIFICATE_VERIFICATION=false
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_FEED_SINCE
ENV ZEEK_INTEL_FEED_SINCE=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_REFRESH_THREADS
ENV ZEEK_INTEL_REFRESH_THREADS=2
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_ITEM_EXPIRATION
ENV ZEEK_INTEL_ITEM_EXPIRATION=-1min
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_AUTO_ANALYZE_PCAP_THREADS
ENV ZEEK_AUTO_ANALYZE_PCAP_THREADS=1
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_AUTO_ANALYZE_PCAP_FILES
ENV ZEEK_AUTO_ANALYZE_PCAP_FILES=false
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_REFRESH_CRON_EXPRESSION
ENV ZEEK_INTEL_REFRESH_CRON_EXPRESSION=
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_REFRESH_ON_DEPLOY
ENV ZEEK_INTEL_REFRESH_ON_DEPLOY=false
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_INTEL_REFRESH_ON_STARTUP
ENV ZEEK_INTEL_REFRESH_ON_STARTUP=false
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 ZEEK_PCAP_PROCESSOR
ENV ZEEK_PCAP_PROCESSOR=true
                        
# 2026-06-01 22:56:00  0.00B 设置环境变量 AUTO_TAG
ENV AUTO_TAG=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG PCAP_NODE_NAME=malcolm
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG PCAP_FILTER=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG PCAP_IFACE_TWEAK=false
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG PCAP_IFACE=lo
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_ROTATED_PCAP=false
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_LIVE_CAPTURE=false
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG PCAP_MONITOR_HOST=pcap-monitor
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG PCAP_PIPELINE_VERBOSITY=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG PCAP_PROCESSED_DIRECTORY=/pcap/processed
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_UPLOAD_DIRECTORY=/zeek/upload
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_CUSTOM_PATH=/usr/local/zeek/share/zeek/site/custom
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_PATH=/usr/local/zeek/share/zeek/site/intel
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_EXTRACTOR_PATH=/zeek/extract_files
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_EXTRACTOR_MODE=none
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_FEED_SSL_CERTIFICATE_VERIFICATION=false
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_FEED_SINCE=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_REFRESH_THREADS=2
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_ITEM_EXPIRATION=-1min
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_REFRESH_CRON_EXPRESSION=
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_REFRESH_ON_DEPLOY=false
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_INTEL_REFRESH_ON_STARTUP=false
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_AUTO_ANALYZE_PCAP_THREADS=1
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_AUTO_ANALYZE_PCAP_FILES=false
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG ZEEK_PCAP_PROCESSOR=true
                        
# 2026-06-01 22:56:00  0.00B 定义构建参数
ARG AUTO_TAG=true
                        
# 2026-06-01 22:56:00  0.00B 执行命令并创建新的镜像层
RUN |2 DEFAULT_UID=1000 DEFAULT_GID=1000 /bin/sh -x -c mkdir -p /tmp/logs &&     cd /tmp/logs &&     export ZEEK_THIRD_PARTY_PLUGINS_COUNT=$(echo "$ZEEK_THIRD_PARTY_PLUGINS_GREP" | grep -P -o "\([^)]+\)" | head -n 1 | sed "s/^(//" | sed "s/)$//" | tr '|' '\n' | wc -l) &&     export ZEEK_THIRD_PARTY_SCRIPTS_COUNT=$(echo "$ZEEK_THIRD_PARTY_SCRIPTS_GREP" | grep -P -o "\([^)]+\)" | head -n 1 | sed "s/^(//" | sed "s/)$//" | tr '|' '\n' | wc -l) &&     "$ZEEK_DIR"/bin/zeek-offline -NN local >zeeknn.log 2>/dev/null &&       bash -c "(( $(grep -cP "$ZEEK_THIRD_PARTY_PLUGINS_GREP" zeeknn.log) >= $ZEEK_THIRD_PARTY_PLUGINS_COUNT )) && echo $ZEEK_THIRD_PARTY_PLUGINS_COUNT' Zeek plugins loaded correctly' || (echo 'One or more Zeek plugins did not load correctly' && cat zeeknn.log && exit 1)" &&     "$ZEEK_DIR"/bin/zeek-offline -C -r /tmp/pcaps/udp.pcap local policy/misc/loaded-scripts >loaded_scripts.log 2>/dev/null &&       bash -c "(( $(grep -cP "$ZEEK_THIRD_PARTY_SCRIPTS_GREP" loaded_scripts.log) == $ZEEK_THIRD_PARTY_SCRIPTS_COUNT )) && echo $ZEEK_THIRD_PARTY_SCRIPTS_COUNT' Zeek scripts loaded correctly' || (echo 'One or more Zeek scripts did not load correctly' && cat loaded_scripts.log && exit 1)" &&     cd /tmp &&     rm -rf /tmp/logs /tmp/pcaps # buildkit
                        
# 2026-06-01 22:55:58  0.00B 设置环境变量 ZEEK_THIRD_PARTY_SCRIPTS_GREP
ENV ZEEK_THIRD_PARTY_SCRIPTS_GREP=(bro-is-darknet/main|bro-simple-scan/scan|bzar/main|callstranger-detector/callstranger|cve-2020-0601/cve-2020-0601|cve-2020-13777/cve-2020-13777|CVE-2020-16898/CVE-2020-16898|CVE-2021-1675/main|CVE-2021-31166/detect|CVE-2021-38647/omigod|CVE-2021-41773/CVE_2021_41773|CVE-2021-42292/main|cve-2021-44228/CVE_2021_44228|cve-2022-21907/main|cve-2022-22954/main|CVE-2022-23270-PPTP/main|CVE-2022-24491/main|CVE-2022-24497/main|cve-2022-26809/main|CVE-2022-26937/main|CVE-2022-30216/main|CVE-2022-3602/__load__|hassh/hassh|http-more-files-names/main|ja4/main|pingback/detect|ripple20/ripple20|SIGRed/CVE-2020-1350|zeek-agenttesla-detector/main|zeek-asyncrat-detector/main|zeek-EternalSafety/main|zeek-httpattacks/main|zeek-netsupport-detector/main|zeek-quasarrat-detector/main|zeek-sniffpass/__load__|zeek-strrat-detector/main|zerologon/main|zeek-long-connections/main)\.(zeek|bro)
                        
# 2026-06-01 22:55:58  0.00B 设置环境变量 ZEEK_THIRD_PARTY_PLUGINS_GREP
ENV ZEEK_THIRD_PARTY_PLUGINS_GREP=(Zeek::Spicy|ANALYZER_SPICY_OSPF|ANALYZER_SPICY_OPENVPN_UDP\b|ANALYZER_SPICY_IPSEC_UDP\b|ANALYZER_SPICY_TFTP|ANALYZER_SPICY_WIREGUARD|ANALYZER_C1222_UDP|ANALYZER_C1222_TCP|ANALYZER_SPICY_HART_IP_UDP|ANALYZER_SPICY_HART_IP_TCP|ANALYZER_ROC_PLUS_TCP|ANALYZER_ROC_PLUS_UDP|ANALYZER_OMRON_FINS_TCP|ANALYZER_OMRON_FINS_UDP|ANALYZER_SYNCHROPHASOR_TCP|ANALYZER_GENISYS_TCP|ANALYZER_SPICY_GE_SRTP|ANALYZER_SPICY_PROFINET_IO_CM|ANALYZER_S7COMM_TCP|Corelight::PE_XOR|ICSNPP::BACnet|ICSNPP::BSAP|ICSNPP::ENIP|ICSNPP::ETHERCAT|ICSNPP::OPCUA_Binary|Salesforce::GQUIC|Zeek::PROFINET|Zeek::TDS|Seiso::Kafka|JGras::FuzzyHashing)
                        
# 2026-06-01 22:55:58  47.04MB 执行命令并创建新的镜像层
RUN |2 DEFAULT_UID=1000 DEFAULT_GID=1000 /bin/sh -x -c groupadd --gid ${DEFAULT_GID} ${PUSER} &&     useradd -M --uid ${DEFAULT_UID} --gid ${DEFAULT_GID} --home /nonexistent ${PUSER} &&     usermod -a -G tty ${PUSER} &&     cp "${ZEEK_DIR}"/bin/zeek "${ZEEK_DIR}"/bin/zeek-offline &&     chown root:${PGROUP} "${ZEEK_DIR}"/bin/zeek "${ZEEK_DIR}"/bin/capstats &&       setcap 'CAP_NET_RAW+eip CAP_NET_ADMIN+eip' "${ZEEK_DIR}"/bin/zeek &&       setcap 'CAP_NET_RAW+eip CAP_NET_ADMIN+eip' "${ZEEK_DIR}"/bin/capstats &&     touch "${SUPERCRONIC_CRONTAB}" &&     chown -R ${DEFAULT_UID}:${DEFAULT_GID} "${ZEEK_DIR}"/share/zeek/site/intel "${SUPERCRONIC_CRONTAB}" &&     ln -sfr /usr/local/bin/pcap_processor.py /usr/local/bin/pcap_zeek_processor.py &&     ln -sfr /usr/local/bin/malcolm_utils.py "${ZEEK_DIR}"/bin/malcolm_utils.py &&     ln -sfr /usr/local/bin/malcolm_constants.py "${ZEEK_DIR}"/bin/malcolm_constants.py &&     ln -sfr /usr/local/bin/zeek_intel_setup.sh "${ZEEK_DIR}"/bin/zeek_intel_setup.sh &&     ln -sfr /usr/local/bin/zeekdeploy.sh "${ZEEK_DIR}"/bin/zeekdeploy.sh &&     ln -sfr /usr/local/bin/zeek*threat*.py "${ZEEK_DIR}"/bin/ # buildkit
                        
# 2026-06-01 22:55:58  89.44KB 复制文件或目录到容器中
ADD --chmod=644 zeek/config/*.zeek /usr/local/zeek/share/zeek/site/ # buildkit
                        
# 2026-06-01 22:55:58  15.44KB 复制文件或目录到容器中
ADD --chmod=644 zeek/config/*.txt /usr/local/zeek/share/zeek/site/ # buildkit
                        
# 2026-06-01 22:55:58  2.13KB 复制文件或目录到容器中
ADD --chmod=644 zeek/supervisord.conf /etc/supervisord.conf # buildkit
                        
# 2026-06-01 22:55:58  100.00B 复制文件或目录到容器中
ADD shared/pcaps /tmp/pcaps # buildkit
                        
# 2026-06-01 22:55:58  1.03KB 复制文件或目录到容器中
ADD --chmod=644 shared/bin/pcap_utils.py /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:55:58  38.21KB 复制文件或目录到容器中
ADD --chmod=755 shared/bin/pcap_processor.py /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:55:58  113.49KB 复制文件或目录到容器中
ADD zeek/scripts /usr/local/bin # buildkit
                        
# 2026-06-01 22:55:58  1.77KB 复制文件或目录到容器中
ADD --chmod=755 shared/bin/netdev-json.sh /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:55:58  703.00B 复制文件或目录到容器中
ADD --chmod=755 container-health-scripts/zeek.sh /usr/local/bin/container_health.sh # buildkit
                        
# 2026-06-01 22:55:58  7.14KB 复制文件或目录到容器中
ADD --chmod=755 shared/bin/service_check_passthrough.sh /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:55:58  10.93KB 复制文件或目录到容器中
ADD --chmod=755 shared/bin/docker-uid-gid-setup.sh /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:55:58  2.46MB 复制新文件或目录到容器中
COPY --chmod=755 /goStatic /usr/bin/goStatic # buildkit
                        
# 2026-06-01 22:55:57  796.02MB 执行命令并创建新的镜像层
RUN |2 DEFAULT_UID=1000 DEFAULT_GID=1000 /bin/sh -x -c export BINARCH=$(uname -m | sed 's/x86_64/amd64/' | sed 's/aarch64/arm64/') &&     apt-get -q update &&     apt-get install -q -y --no-install-recommends       bc       binutils       bison       ca-certificates       ccache       cmake       cppzmq-dev       curl       file       flex       g++       gcc       git       gnupg2       iproute2       jq       less       libatomic1       libcap2-bin       libfl-dev       libfl2       libfuzzy-dev       libfuzzy2       libgoogle-perftools4       libhiredis-dev       libhiredis1.1.0       libkrb5-3       libmaxminddb-dev       libmaxminddb0       libpcap-dev       libpcap0.8       librdkafka++1       librdkafka-dev       librdkafka1       libssl-dev       libssl3       libtcmalloc-minimal4       libtlsh-dev       libtlsh0       libunwind8       libzmq3-dev       libzmq5       locales-all       make       moreutils       ninja-build       openssl       procps       psmisc       python3       python3-bs4       python3-git       python3-pip       python3-semantic-version       python3-setuptools       python3-tz       python3-wheel       python3-yaml       python3-zmq       rsync       swig       tini       vim-tiny       xxd       zlib1g-dev &&     python3 -m pip install --break-system-packages --no-cache-dir -r /usr/local/src/requirements.txt &&     curl -fsSL -o /usr/local/bin/supercronic "${SUPERCRONIC_URL}${BINARCH}" &&       chmod +x /usr/local/bin/supercronic &&     cd "${ZEEK_DIR}"/share/zeek/site &&       /usr/share/nodejs/corepack/shims/npm install redis &&     cd /tmp &&     mkdir -p "${CCACHE_DIR}" &&     zkg autoconfig --force &&     bash /usr/local/bin/zeek_install_plugins.sh &&       ( find "${ZEEK_DIR}"/lib "${ZEEK_DIR}"/var/lib/zkg \( -path "*/build/*" -o -path "*/CMakeFiles/*" \) -type f -name "*.*" -print0 | xargs -0 -I XXX bash -c 'file "XXX" | sed "s/^.*:[[:space:]]//" | grep -Pq "(ELF|gzip)" && rm -f "XXX"' || true ) &&       ( find "${ZEEK_DIR}"/var/lib/zkg/clones -type d -name .git -execdir bash -c "pwd; du -sh; git pull --depth=1 --ff-only; git reflog expire --expire=all --all; git tag -l | xargs -r git tag -d; git gc --prune=all; du -sh" \; ) &&       rm -rf "${ZEEK_DIR}"/var/lib/zkg/scratch &&       rm -rf "${ZEEK_DIR}"/lib/zeek/python/zeekpkg/__pycache__ &&       ( find "${ZEEK_DIR}/"var/lib/zkg/clones/package/ja4 -mindepth 1 -maxdepth 1 -type d ! \( -name zeek -o -name '.git*' \) -exec rm -rf "{}" \; || true ) &&       ( find "${ZEEK_DIR}/" -type f -exec file "{}" \; | grep -Pi "ELF 64-bit.*not stripped" | sed 's/:.*//' | xargs -l -r strip --strip-unneeded || true ) &&       ( find "${ZEEK_DIR}"/lib/zeek/plugins/packages -type f -name "*.hlto" -exec chmod 755 "{}" \; || true ) &&       ( find "${ZEEK_DIR}"/var/lib/zkg/clones -mindepth 3 -maxdepth 3 -type d \( -iname 'test*' -o -iname 'pcap*' -o -iname "trace*" \) -exec rm -rf "{}" \; || true ) &&     mkdir -p "${ZEEK_DIR}"/share/zeek/site/intel/STIX &&       mkdir -p "${ZEEK_DIR}"/share/zeek/site/intel/MISP &&       mkdir -p "${ZEEK_DIR}"/share/zeek/site/intel/Google &&       mkdir -p "${ZEEK_DIR}"/share/zeek/site/intel/Mandiant &&       mkdir -p "${ZEEK_DIR}"/share/zeek/site/custom &&       touch "${ZEEK_DIR}"/share/zeek/site/intel/__load__.zeek &&       touch "${ZEEK_DIR}"/share/zeek/site/custom/__load__.zeek &&     /usr/local/bin/zeek_iana_lookup_generator.py --output-file "${ZEEK_DIR}"/share/zeek/site/iana_service_map.txt &&     cd /usr/lib/locale &&       ( ls | grep -Piv "^(en|en_US|en_US\.utf-?8|C\.utf-?8)$" | xargs -l -r rm -rf ) &&     cd /tmp &&     apt-get clean &&       rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* /var/cache/*/* # buildkit
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 SUPERCRONIC_CRONTAB
ENV SUPERCRONIC_CRONTAB=/usr/local/zeek/etc/crontab
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 SUPERCRONIC_URL
ENV SUPERCRONIC_URL=https://github.com/aptible/supercronic/releases/download/v0.2.46/supercronic-linux-
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 SUPERCRONIC_VERSION
ENV SUPERCRONIC_VERSION=0.2.46
                        
# 2026-06-01 22:15:17  155.00B 复制文件或目录到容器中
ADD --chmod=644 zeek/requirements.txt /usr/local/src/requirements.txt # buildkit
                        
# 2026-06-01 22:15:17  0.00B 复制文件或目录到容器中
ADD zeek/custom-pkg /usr/local/zeek/custom-pkg # buildkit
                        
# 2026-06-01 22:15:17  6.67KB 复制文件或目录到容器中
ADD --chmod=644 scripts/malcolm_constants.py /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:15:17  52.21KB 复制文件或目录到容器中
ADD --chmod=644 scripts/malcolm_utils.py /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:15:17  7.30KB 复制文件或目录到容器中
ADD --chmod=755 zeek/scripts/zeek_iana_lookup_generator.py /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:15:17  7.72KB 复制文件或目录到容器中
ADD --chmod=755 zeek/scripts/zeek_install_plugins.sh /usr/local/bin/ # buildkit
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 CCACHE_COMPRESS
ENV CCACHE_COMPRESS=1
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 CCACHE_DIR
ENV CCACHE_DIR=/var/spool/ccache
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 PATH
ENV PATH=/usr/local/zeek/bin:/usr/local/zeek/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 ZEEK_DIR
ENV ZEEK_DIR=/usr/local/zeek
                        
# 2026-06-01 22:15:17  0.00B 指定运行容器时使用的用户
USER root
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 PUSER_RLIMIT_UNLOCK
ENV PUSER_RLIMIT_UNLOCK=true
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 PUSER_PRIV_DROP
ENV PUSER_PRIV_DROP=false
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 PGROUP
ENV PGROUP=zeeker
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 PUSER
ENV PUSER=zeeker
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 DEFAULT_GID
ENV DEFAULT_GID=1000
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 DEFAULT_UID
ENV DEFAULT_UID=1000
                        
# 2026-06-01 22:15:17  0.00B 定义构建参数
ARG DEFAULT_GID=1000
                        
# 2026-06-01 22:15:17  0.00B 定义构建参数
ARG DEFAULT_UID=1000
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 PYTHONUNBUFFERED
ENV PYTHONUNBUFFERED=1
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 PYTHONDONTWRITEBYTECODE
ENV PYTHONDONTWRITEBYTECODE=1
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 TERM
ENV TERM=xterm
                        
# 2026-06-01 22:15:17  0.00B 设置环境变量 DEBIAN_FRONTEND
ENV DEBIAN_FRONTEND=noninteractive
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL org.opencontainers.image.description=Malcolm container providing Zeek
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL org.opencontainers.image.title=ghcr.io/idaholab/malcolm/zeek
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL org.opencontainers.image.vendor=Idaho National Laboratory
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL org.opencontainers.image.source=https://github.com/idaholab/Malcolm
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL org.opencontainers.image.documentation=https://github.com/idaholab/Malcolm/blob/main/README.md
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL org.opencontainers.image.url=https://github.com/idaholab/Malcolm
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL org.opencontainers.image.authors=malcolm@inl.gov
                        
# 2026-06-01 22:15:17  0.00B 添加元数据标签
LABEL maintainer=malcolm@inl.gov
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.description=Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.title=Zeek
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.licenses=BSD-3-Clause
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.vendor=The Zeek Project
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.revision=1882370401b01ec4e54538d23e02ddcd7e6937ce
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.version=8.1.2
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.source=https://github.com/zeek/zeek
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.documentation=https://docs.zeek.org
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.url=https://zeek.org
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.authors=info@zeek.org
                        
# 2026-04-21 00:07:50  0.00B 添加元数据标签
LABEL org.opencontainers.image.created=2026-04-20T16:07:27+00:00
                        
# 2026-04-21 00:07:50  0.00B 定义构建参数
ARG CREATED_DATE=2026-04-20T16:07:27+00:00
                        
# 2026-04-21 00:07:50  0.00B 定义构建参数
ARG GIT_COMMIT=1882370401b01ec4e54538d23e02ddcd7e6937ce
                        
# 2026-04-21 00:07:50  0.00B 定义构建参数
ARG ZEEK_VERSION=8.1.2
                        
# 2026-04-21 00:07:50  0.00B 设置环境变量 PYTHONPATH
ENV PYTHONPATH=/usr/local/zeek/lib/zeek/python:
                        
# 2026-04-21 00:07:50  0.00B 设置环境变量 PATH
ENV PATH=/usr/local/zeek/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
                        
# 2026-04-21 00:07:50  222.36MB 复制新文件或目录到容器中
COPY /usr/local/zeek /usr/local/zeek # buildkit
                        
# 2026-04-21 00:07:49  263.79MB 执行命令并创建新的镜像层
RUN /bin/sh -x -c apt-get -q update  && apt-get upgrade -q -y  && apt-get install -q -y --no-install-recommends      ca-certificates      git      jq      libmaxminddb0      libnode115      libpcap0.8      libpython3.13      libssl3      libuv1      libz1      libzmq5      net-tools      procps      python3-git      python3-minimal      python3-semantic-version      python3-websocket      python3-websockets  && apt-get clean  && rm -rf /var/lib/apt/lists/* # buildkit
                        
# 2026-04-20 23:56:49  61.00B 执行命令并创建新的镜像层
RUN /bin/sh -x -c echo 'Acquire::https::timeout "180";' >> /etc/apt/apt.conf.d/99-timeouts # buildkit
                        
# 2026-04-20 23:56:49  30.00B 执行命令并创建新的镜像层
RUN /bin/sh -x -c echo 'Acquire::http::timeout "180";' > /etc/apt/apt.conf.d/99-timeouts # buildkit
                        
# 2026-04-20 23:56:49  22.00B 执行命令并创建新的镜像层
RUN /bin/sh -x -c echo 'Acquire::Retries "3";' > /etc/apt/apt.conf.d/80-retries # buildkit
                        
# 2026-04-20 23:56:49  0.00B 
SHELL [/bin/sh -x -c]
                        
# 2026-04-06 08:00:00  78.61MB 
# debian.sh --arch 'amd64' out/ 'trixie' '@1775433600'
                        
                    

镜像信息

{
    "Id": "sha256:1248de196bf6f34dde4755ccb3ad6b50a99a0dba9d4f60fe37b0207cb5213c5f",
    "RepoTags": [
        "ghcr.io/idaholab/malcolm/zeek:26.06.0",
        "swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek:26.06.0"
    ],
    "RepoDigests": [
        "ghcr.io/idaholab/malcolm/zeek@sha256:7fd6eb67c87ed539ecac62a22a3cdd705c678688a0379f03fcb13a4401e7c502",
        "swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/idaholab/malcolm/zeek@sha256:1392060b912b602f1c4f2f0ae80df5b27b1046374b2801dc0721df2dbdbf09fb"
    ],
    "Parent": "",
    "Comment": "buildkit.dockerfile.v0",
    "Created": "2026-06-01T14:56:00.032245616Z",
    "Container": "",
    "ContainerConfig": null,
    "DockerVersion": "",
    "Author": "",
    "Config": {
        "Hostname": "",
        "Domainname": "",
        "User": "root",
        "AttachStdin": false,
        "AttachStdout": false,
        "AttachStderr": false,
        "Tty": false,
        "OpenStdin": false,
        "StdinOnce": false,
        "Env": [
            "PATH=/usr/local/zeek/bin:/usr/local/zeek/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
            "PYTHONPATH=/usr/local/zeek/lib/zeek/python:",
            "DEBIAN_FRONTEND=noninteractive",
            "TERM=xterm",
            "PYTHONDONTWRITEBYTECODE=1",
            "PYTHONUNBUFFERED=1",
            "DEFAULT_UID=1000",
            "DEFAULT_GID=1000",
            "PUSER=zeeker",
            "PGROUP=zeeker",
            "PUSER_PRIV_DROP=false",
            "PUSER_RLIMIT_UNLOCK=true",
            "ZEEK_DIR=/usr/local/zeek",
            "CCACHE_DIR=/var/spool/ccache",
            "CCACHE_COMPRESS=1",
            "SUPERCRONIC_VERSION=0.2.46",
            "SUPERCRONIC_URL=https://github.com/aptible/supercronic/releases/download/v0.2.46/supercronic-linux-",
            "SUPERCRONIC_CRONTAB=/usr/local/zeek/etc/crontab",
            "ZEEK_THIRD_PARTY_PLUGINS_GREP=(Zeek::Spicy|ANALYZER_SPICY_OSPF|ANALYZER_SPICY_OPENVPN_UDP\\b|ANALYZER_SPICY_IPSEC_UDP\\b|ANALYZER_SPICY_TFTP|ANALYZER_SPICY_WIREGUARD|ANALYZER_C1222_UDP|ANALYZER_C1222_TCP|ANALYZER_SPICY_HART_IP_UDP|ANALYZER_SPICY_HART_IP_TCP|ANALYZER_ROC_PLUS_TCP|ANALYZER_ROC_PLUS_UDP|ANALYZER_OMRON_FINS_TCP|ANALYZER_OMRON_FINS_UDP|ANALYZER_SYNCHROPHASOR_TCP|ANALYZER_GENISYS_TCP|ANALYZER_SPICY_GE_SRTP|ANALYZER_SPICY_PROFINET_IO_CM|ANALYZER_S7COMM_TCP|Corelight::PE_XOR|ICSNPP::BACnet|ICSNPP::BSAP|ICSNPP::ENIP|ICSNPP::ETHERCAT|ICSNPP::OPCUA_Binary|Salesforce::GQUIC|Zeek::PROFINET|Zeek::TDS|Seiso::Kafka|JGras::FuzzyHashing)",
            "ZEEK_THIRD_PARTY_SCRIPTS_GREP=(bro-is-darknet/main|bro-simple-scan/scan|bzar/main|callstranger-detector/callstranger|cve-2020-0601/cve-2020-0601|cve-2020-13777/cve-2020-13777|CVE-2020-16898/CVE-2020-16898|CVE-2021-1675/main|CVE-2021-31166/detect|CVE-2021-38647/omigod|CVE-2021-41773/CVE_2021_41773|CVE-2021-42292/main|cve-2021-44228/CVE_2021_44228|cve-2022-21907/main|cve-2022-22954/main|CVE-2022-23270-PPTP/main|CVE-2022-24491/main|CVE-2022-24497/main|cve-2022-26809/main|CVE-2022-26937/main|CVE-2022-30216/main|CVE-2022-3602/__load__|hassh/hassh|http-more-files-names/main|ja4/main|pingback/detect|ripple20/ripple20|SIGRed/CVE-2020-1350|zeek-agenttesla-detector/main|zeek-asyncrat-detector/main|zeek-EternalSafety/main|zeek-httpattacks/main|zeek-netsupport-detector/main|zeek-quasarrat-detector/main|zeek-sniffpass/__load__|zeek-strrat-detector/main|zerologon/main|zeek-long-connections/main)\\.(zeek|bro)",
            "AUTO_TAG=true",
            "ZEEK_PCAP_PROCESSOR=true",
            "ZEEK_INTEL_REFRESH_ON_STARTUP=false",
            "ZEEK_INTEL_REFRESH_ON_DEPLOY=false",
            "ZEEK_INTEL_REFRESH_CRON_EXPRESSION=",
            "ZEEK_AUTO_ANALYZE_PCAP_FILES=false",
            "ZEEK_AUTO_ANALYZE_PCAP_THREADS=1",
            "ZEEK_INTEL_ITEM_EXPIRATION=-1min",
            "ZEEK_INTEL_REFRESH_THREADS=2",
            "ZEEK_INTEL_FEED_SINCE=",
            "ZEEK_INTEL_FEED_SSL_CERTIFICATE_VERIFICATION=false",
            "ZEEK_EXTRACTOR_MODE=none",
            "ZEEK_EXTRACTOR_PATH=/zeek/extract_files",
            "ZEEK_INTEL_PATH=/usr/local/zeek/share/zeek/site/intel",
            "ZEEK_CUSTOM_PATH=/usr/local/zeek/share/zeek/site/custom",
            "ZEEK_UPLOAD_DIRECTORY=/zeek/upload",
            "PCAP_PROCESSED_DIRECTORY=/pcap/processed",
            "PCAP_PIPELINE_VERBOSITY=",
            "PCAP_MONITOR_HOST=pcap-monitor",
            "ZEEK_LIVE_CAPTURE=false",
            "ZEEK_ROTATED_PCAP=false",
            "PCAP_IFACE=lo",
            "PCAP_IFACE_TWEAK=false",
            "PCAP_FILTER=",
            "PCAP_NODE_NAME=malcolm",
            "ZEEK_DISABLE_STATS=true",
            "ZEEK_DISABLE_LOG_PASSWORDS=",
            "ZEEK_DISABLE_SSL_VALIDATE_CERTS=",
            "ZEEK_DISABLE_TRACK_ALL_ASSETS=",
            "ZEEK_DISABLE_DETECT_ROUTERS=true",
            "ZEEK_DISABLE_IANA_LOOKUP=",
            "ZEEK_DISABLE_BEST_GUESS_ICS=true",
            "ZEEK_DISABLE_SPICY_IPSEC=",
            "ZEEK_DISABLE_SPICY_LDAP=",
            "ZEEK_DISABLE_SPICY_OPENVPN=",
            "ZEEK_DISABLE_SPICY_QUIC=true",
            "ZEEK_DISABLE_SPICY_STUN=",
            "ZEEK_DISABLE_SPICY_TAILSCALE=",
            "ZEEK_DISABLE_SPICY_WIREGUARD=",
            "ZEEK_DISABLE_SPICY_ZIP=true",
            "ZEEK_C1222_AUTHENTICATION_VALUE=true",
            "ZEEK_C1222_IDENTIFICATION_SERVICE=true",
            "ZEEK_C1222_READ_WRITE_SERVICE=true",
            "ZEEK_C1222_LOGON_SECURITY_SERVICE=true",
            "ZEEK_C1222_WAIT_SERVICE=true",
            "ZEEK_C1222_DEREG_REG_SERVICE=true",
            "ZEEK_C1222_RESOLVE_SERVICE=true",
            "ZEEK_C1222_TRACE_SERVICE=true",
            "ZEEK_SYNCHROPHASOR_DETAILED=",
            "ZEEK_OMRON_FINS_DETAILED=true",
            "ZEEK_KAFKA_ENABLED=",
            "ZEEK_KAFKA_BROKERS=kafka.local:9091",
            "ZEEK_KAFKA_TOPIC=zeek",
            "ZEEK_FILE_ANALYZER_TIMEOUT_SEC=5",
            "PUSER_CHOWN=/usr/local/zeek/etc;/usr/local/zeek/share/zeek/site/custom;/usr/local/zeek/share/zeek/site/intel;/usr/local/zeek/share/zeekctl;/usr/local/zeek/spool",
            "BUILD_DATE=2026-06-01T14:15:01Z",
            "MALCOLM_VERSION=26.06.0",
            "VCS_REVISION=0e21be1"
        ],
        "Cmd": [
            "/usr/local/bin/supervisord",
            "-c",
            "/etc/supervisord.conf",
            "-n"
        ],
        "ArgsEscaped": true,
        "Image": "",
        "Volumes": {
            "/usr/local/zeek/share/zeek/site/intel": {}
        },
        "WorkingDir": "",
        "Entrypoint": [
            "/usr/bin/tini",
            "--",
            "/usr/local/bin/docker-uid-gid-setup.sh",
            "/usr/local/bin/docker_entrypoint.sh",
            "/usr/local/bin/service_check_passthrough.sh",
            "-s",
            "zeek"
        ],
        "OnBuild": null,
        "Labels": {
            "maintainer": "malcolm@inl.gov",
            "org.opencontainers.image.authors": "malcolm@inl.gov",
            "org.opencontainers.image.created": "2026-06-01T14:15:01Z",
            "org.opencontainers.image.description": "Malcolm container providing Zeek",
            "org.opencontainers.image.documentation": "https://github.com/idaholab/Malcolm/blob/main/README.md",
            "org.opencontainers.image.licenses": "BSD-3-Clause",
            "org.opencontainers.image.revision": "0e21be1",
            "org.opencontainers.image.source": "https://github.com/idaholab/Malcolm",
            "org.opencontainers.image.title": "ghcr.io/idaholab/malcolm/zeek",
            "org.opencontainers.image.url": "https://github.com/idaholab/Malcolm",
            "org.opencontainers.image.vendor": "Idaho National Laboratory",
            "org.opencontainers.image.version": "26.06.0"
        },
        "Shell": [
            "/bin/sh",
            "-x",
            "-c"
        ]
    },
    "Architecture": "amd64",
    "Os": "linux",
    "Size": 1410626353,
    "GraphDriver": {
        "Data": {
            "LowerDir": "/var/lib/docker/overlay2/33af24188fc0c7e41b9f4cb4ecb4d885b9a6ed3e8cec8a6a64c8186dc87b930b/diff:/var/lib/docker/overlay2/983ce4342f6e66b13f12c893ac41c21ff5ee18f06b72cd20d13b98827c4077f2/diff:/var/lib/docker/overlay2/d2c7dd17413359dfce5575fa183508767b125e43e4ecc8f86172d8e66472753d/diff:/var/lib/docker/overlay2/2224b406cb96df94f83baf2ccdd0c49d522a5f888e296006fe00ff3a7249e4af/diff:/var/lib/docker/overlay2/fe7078f4f08b73fab5f7e267a1c077205b8589b71f2595a95b650b21af772ae0/diff:/var/lib/docker/overlay2/38b68dcc79dd0af14196221a34d39ad26d54c09799cc82d6fbaaff7863bb90ef/diff:/var/lib/docker/overlay2/e5466c3ca9c3d05b7e569df84b7f8094596adc897c9c985585765634d5064da1/diff:/var/lib/docker/overlay2/a40d9c893f072824b6167a19c6460a717f481ea572894765f3b7523a28feaf8f/diff:/var/lib/docker/overlay2/ce01ef5eea7cfe5997d24008eb9194e869fbf9effa091db7beb835d5beeddb20/diff:/var/lib/docker/overlay2/866bee95e87a3f65968f41c051e5ae3ea00dd1408498af97a3ed1afe57098283/diff:/var/lib/docker/overlay2/5dadf2a9be149811eace7a572407361532d415a50df9443c4952854a896794eb/diff:/var/lib/docker/overlay2/ffee98235ae7139511bf4eb7219c80a5c6899bc1d3bcab1e639dcc0ded147313/diff:/var/lib/docker/overlay2/3d634b265fbb7b85817e4a34a4f1da23420acf804fb6ed63fbf49f6fe866366e/diff:/var/lib/docker/overlay2/9369bd52e09546d33d298787511f7d715ff07419350e90e8bf863775e7ee4519/diff:/var/lib/docker/overlay2/70b8a865c41c60645e9f9f245d4dd4e32c2bde741df4b4974bc4cd3cfd510c01/diff:/var/lib/docker/overlay2/7b7514785771a12604e839dd58f3f5bb73fa46d8bd22b4ce6ca739942b1e8d42/diff:/var/lib/docker/overlay2/65a9df0c7a0bc7c1fcf8b8c9eb3553a81a54f7f66c71a92e5f611eea58f1ddca/diff:/var/lib/docker/overlay2/dca672c0d7f347eb10350f30b19d0881ab172798a02903f705637b9278d211a4/diff:/var/lib/docker/overlay2/0a9919f8f64f47b953dc5617c7c165b24a62b46c2ba9df103567133d759522c1/diff:/var/lib/docker/overlay2/b904bc89515480b6e21998d5e928042421b64e419387a084ca04e5b1019645aa/diff:/var/lib/docker/overlay2/44ab0e7a03aa334d3bcbf79bc97d05194982736ef23ee4adca1ad13d7f7dbada/diff:/var/lib/docker/overlay2/70b224e0702f3d3197bc70f2db1e02db339017dbc2da066f742a717cd772c043/diff:/var/lib/docker/overlay2/0972eb1b0a6e6dc252342bedad03e627d5b879b3be216a86c144783876663b2c/diff:/var/lib/docker/overlay2/15d45063b9832dd217576a325969b69475cd6d154b3020741f3154d8eaabb19e/diff:/var/lib/docker/overlay2/a9a75f60504af802e34265de9ba0d2f6f37d18228e74fe4368d4d143e5916840/diff:/var/lib/docker/overlay2/1a3b1c1b80ab3a0f1b38ff73139314e86e17237b2a60acf75f135745c22d2d02/diff",
            "MergedDir": "/var/lib/docker/overlay2/431dd6cffbc9b5f2cb43c9cc854acc2ab6629612eead0f358e19a3ae25d3bde6/merged",
            "UpperDir": "/var/lib/docker/overlay2/431dd6cffbc9b5f2cb43c9cc854acc2ab6629612eead0f358e19a3ae25d3bde6/diff",
            "WorkDir": "/var/lib/docker/overlay2/431dd6cffbc9b5f2cb43c9cc854acc2ab6629612eead0f358e19a3ae25d3bde6/work"
        },
        "Name": "overlay2"
    },
    "RootFS": {
        "Type": "layers",
        "Layers": [
            "sha256:60e70dddd9ea3b1c77c62fe78be1d9f485706b6fe6052c3d88612bd8f56acd67",
            "sha256:2a2fab0b57c863623e47035b951ea0abea2fe2d22d3f1aac51aebbae8c4869d6",
            "sha256:c565e5f0b382a1fd1a7019ffcdb009c3fcd3feb9f448c235da5493a9ddf3f87c",
            "sha256:b6d3d41aab73d3773642c23531898d0f7f2b5e8de4afca48cadd4f63ae22e246",
            "sha256:feb596a5865ce5e1cca2af0a3d9606303cf212fa7e1ee2252e56f4f72dc664c6",
            "sha256:75f232e3a2693238524e2e554c3aec2deb8f8b09ea7becfe6407c89be029ebe0",
            "sha256:f1a9932c2823bdd4a8a47583c277376a6932edabf789514d9e66793ff6b81136",
            "sha256:2475d0850d1642eb38308a918a4015dc9424ea09b9c4cafacaa910b8c3da9240",
            "sha256:46d86f102f2aac5bbbbc6f0cd392f6e806f0bea864c203e1ed3dc0d1d9275fdb",
            "sha256:8fcdf92e14f503e920cbb1ca4fc8b326408380dd7be2838d92a9a6815492b458",
            "sha256:4b61ccba65c40c2b543cca6aa5c8a1c111b240f97ee8a7a293adc21bba165773",
            "sha256:9a4854820b950006d4c809e861bfa1365a22f62b2c6515749991c5e1dc5f998d",
            "sha256:704903b43698425881ffe16e126910e5d9e37bf38fa25da0a69bd8ca9f197232",
            "sha256:901c2419a27af3132d0eae035d596d890808b1f1fe4cfc79220dceee9d81da2c",
            "sha256:e725d4b932dc545cb0a03a03558e9bb297348a7fc05b8263b9e52fb6ff446d14",
            "sha256:40974c3d15e123b5ca1fcdf15a4bf0486abb586cdf69f398b802cd0bc65f0a31",
            "sha256:b432a42818f2cad033e0bd71dd254dc9a2f7181bca7fa0cdebe226611f0a555d",
            "sha256:fa1e1a1ef001198506e92c0ee3af2c8966652acaaf6dc5350c5327a9b56949ad",
            "sha256:8e9baa9be681084983596509b943deb2fdaabaa3bceab3fbcaa02cb575075d5e",
            "sha256:f55e52b7083c63585a5b31cb392018fe996e6de1de96723246f255c938f1e8ad",
            "sha256:d6555c4cf23ad460533835567abaa1edf300acfff030c6e6d89439085b5db1ca",
            "sha256:9f435e35196f620a8a254f642ab9f6b817758876b92ca312d2603fa039cc3784",
            "sha256:d348e5f786c171ac449809d4cc2a1d857d89c633f03df61da637d0817b2dd540",
            "sha256:19a67d526ccc11d7c1b749c2c65dcb82f6c7929fca2b6b7ec2e8f73c340c424d",
            "sha256:94d1f3401ba5dfe37ea679acb4d0d69b9eef01107c04094b82f99e5fd245e282",
            "sha256:ea67da48e16932a1a5dace2e6ded6e5018181e0d44f18d6ece72f4d1b7104c9e",
            "sha256:cc3d04b79f0a1108a59c50a073cfec8b53c96aaca107f2d7199d6871b68014eb"
        ]
    },
    "Metadata": {
        "LastTagTime": "2026-06-13T17:57:42.227304953+08:00"
    }
}

更多版本

ghcr.io/idaholab/malcolm/zeek:26.06.0

linux/amd64 ghcr.io1.41GB2026-06-13 17:59
8