Packages

conn-burst

By corelight

Identify bursty connections (large and fast)

credit-card-exposure

By sethhall

Detect credit card numbers in HTTP and SMTP with Bro.

CVE-2017-5638_struts

By initconf

package to detect CVE-2017-5638 struts attack

detect-kaspersky

By initconf

kaspersky

dns_axfr

By srozb

Find and notice DNS zone transfer attempts.

dns-tunnels

By hhzzk

Detect DNS Tunnels attack.

domain-tld

By sethhall

A library for getting the "effective tld" of a domain name.

dovehawk

By dovehawk

MISP+Zeek. Dovehawk is a Zeek Module to import MISP indicators to the Intel Framework and Signature Framework automatically. Reports sightings directly back to MISP as they happen. Supports Zeek Clusters.

dovehawk_dns

By dovehawk

Dovehawk.io Passive DNS Capture Module.

dummy-connections

By hosom

Create dummy connection records.

file-extraction

By hosom

Extract files from network traffic with Bro.

find_smbv1

By klehigh

find SMBv1 activity

fix-ascii

By reservoirlabs

ASCII FIX analyzer package

fix-binary

By reservoirlabs

binary FIX analyzer package

flow_labels

By bricata

Provides mechanisms for managing and using institutional knowledge about a monitored environment to make informed observations of normal and abnormal network activity.

ftp-bruteforce

By initconf

ftp-bruteforce

hassh

By salesforce

HASSH is used to identify specific Client and Server SSH implementations. The fingerprints can be stored, searched and shared in the form of an MD5 fingerprint. This package logs components to ssh.log

http_csp

By srozb

HTTP Content-Security-Policy report parser

http-stalling-detector

By corelight

Detect HTTP stalling attacks like slowloris.

indicator-rules

By anthonykasza

An extension to the Intel Framework. This package faciliates the creation of rules which Zeek can monitor for.

Page 3 of 5, showing 20 record(s) out of 90 total