Packages

aaalm

By nskelsey

Tag and group devices based on a LAN's structure

ACID

By cisagov

ATT&CK-based Control-system Indicator Detection (ACID) is a collection of Zeek scripts designed to detect ATT&CK for ICS behaviors on OT protocols. These events are reported through the Zeek Notice framework.

add-interfaces

By j-gras

Adds cluster node's interface to logs.

add-json

By j-gras

Additional JSON-logging for Zeek.

add-node-names

By j-gras

Adds cluster node name to logs.

anomalous-dns

By jbaggs

A module for tracking and correlating abnormal DNS behavior. Detection of tunneling and C&C through connection duration and volume, request and answer size, DNS request type, and unique queries per domain. Statistical classification of fast flux networks based on A records and ASNs.

appid

By stevesmoot

Leverage nDPI and other info to make informed guess at the application for a connection.

bad-asn

By amarokinc

Adds ASN reputation data of external IP addresses to notice.log if the ASN crosses a predetermined threshold as defined by circl.lu

BinaryHeap

By jmellander

Binary Heap Implementation

blacklist

By initconf

package to manage blacklisted IP address ysing bro

boa-detector

By corelight

A vulnerable Boa web server detector.

bro_notice_correlation

By dopheide

Adds support for multi-notice correlation. For more information, see http://blog.samoehlert.com/correlating-bro-notices or the talk from BroCon 2016.

bro-af_packet-plugin

By j-gras

This plugin provides native AF_Packet support for Zeek.

bro-doctor

By ncsa

A broctl plugin that helps you troubleshoot common problems For cluster-related checks, the package "add-node-names" is recommended.

bro-drwatson

By corelight

Discover and log information discovered in Microsoft DrWatson messages.

bro-fuzzy-hashing

By j-gras

This plugin provides fuzzy hashing for Bro.

bro-hardware

By corelight

Scripts for cases where hardware device identifiers are discovered.

bro-http2

By mitrecnd

A HTTP2 protocol analyzer for the Zeek NSM.

Page 1 of 14, showing 20 record(s) out of 262 total