Packages
By corelight
This plugin adds support for shell-style glob
patterns when loading Zeek scripts. For example, saying
"@load startup.d/*.zeek" will load any Zeek scripts
with a .zeek suffix from the startup.d folder.
By corelight
A Zeek based Gozi malware detector.
By corelight
This package provides some basic analysis for JPEG files.
By reshadp
Add MAC address to all logs.
By corelight
Find and log long-lived connections into a "conn_long" log.
By corelight
This package provides some basic analysis for Mach-o files.
By corelight
A Zeek base NetSupport detector. NetSupport is often abused by attackers in malware.
By corelight
Package that extends the Notice Framework to include
`ACTION_TELEGRAM` for sending messages on notices over Telegram.
By activecm
Find and log open, long-lived connections into "open_conn", "open_ssl", and "open_http" logs.
By corelight
Detects the Google QUIC (GQUIC) protocol and adds "gquic"
to conn.log's "service" field.
By corelight
A Facefish rootkit detector, based on Spicy.
By corelight
An IPSec Zeek protocol analyzer based on Spicy.
By corelight
A Zeek OpenVPN protocol analyzer, based on Spicy.
By corelight
A Zeek OSPF packet analyzer, based on Spicy.
By corelight
A Zeek STUN protocol analyzer based on Spicy.
By corelight
A Wireguard VPN protocol analyzer, based on Spicy.
By corelight
A Zeek based STRRAT malware detector.
By corelight
A plugin to find Windows executables that have been XOR encoded.
Page 3 of 4, showing 20 record(s) out of 66 total