Packages
By ncsa
A broctl plugin that helps you setup capture interfaces
By fatemabw
Find different type of OSes and AV software in your network traffic.
By ncsa
This plugin adds a Site::is_darknet function.
This is useful for scripts that track scan attempts or other probes.
It can handle purely dark address space as well as honeynet space.
By hosom
Generate and log ja3 ssl fingerprints
By theflakes
Raise notices on outgoing files over X bytes in size.
Also raise notices for multiple large outgoing Tx's in Y time frame.
By j-gras
This plugin provides liblognorm integration for Zeek.
By sethhall
Packet source plugin that provides native Myricom SNF v3+v4 support.
By hosom
Packet source plugin that provides native support for NTAPI
By hosom
Add OUI lookup to Bro.
By ntop
Packet source plugin that provides native PF_RING support.
By dopheide
Attempt to identify QUIC protocol
By corelight
Discover successful ShellShock attacks.
By ncsa
Simple, high performance tcp scan detection
By salesforce
Zeek-Sysmon contains a python script that will read in a file, parse JSON Windows Event Logs, generate Zeek events, and forward them to Zeek. Default Zeek-Sysmon scripts log output to files.
By irtimmer
This plugin provides native AF_XDP support for Bro.
By ncsa
ZeroMQ log writer.
By mitre-attack
BZAR - Bro/Zeek ATT&CK-based Analytics and Reporting.
By corelight
Detects CallStranger (CVE) Exploitation Attempts
Page 2 of 14, showing 20 record(s) out of 262 total