Packages
        
        
        
            By corelight        
        This plugin adds support for shell-style glob
patterns when loading Zeek scripts. For example, saying
"@load startup.d/*.zeek" will load any Zeek scripts
with a .zeek suffix from the startup.d folder.        
     
        
        
        
            By corelight        
        A Zeek based Gozi malware detector.        
     
        
        
        
            By corelight        
        This package provides some basic analysis for JPEG files.        
     
        
        
        
            By reshadp        
        Add MAC address to all logs.        
     
        
        
        
            By corelight        
        Find and log long-lived connections into a "conn_long" log.        
     
        
        
        
            By corelight        
        This package provides some basic analysis for Mach-o files.        
     
        
        
        
        
            By corelight        
        A Zeek base NetSupport detector. NetSupport is often abused by attackers in malware.        
     
        
        
        
            By corelight        
        Package that extends the Notice Framework to include
`ACTION_TELEGRAM` for sending messages on notices over Telegram.        
     
        
        
        
            By activecm        
        Find and log open, long-lived connections into "open_conn", "open_ssl", and "open_http" logs.        
     
        
        
        
        
            By corelight        
        Detects the Google QUIC (GQUIC) protocol and adds "gquic"
to conn.log's "service" field.        
     
        
        
        
            By corelight        
        A Facefish rootkit detector, based on Spicy.        
     
        
        
        
            By corelight        
        An IPSec Zeek protocol analyzer based on Spicy.        
     
        
        
        
            By corelight        
        A Zeek OpenVPN protocol analyzer, based on Spicy.        
     
        
        
        
            By corelight        
        A Zeek OSPF packet analyzer, based on Spicy.        
     
        
        
        
            By corelight        
        A Zeek STUN protocol analyzer based on Spicy.        
     
        
        
        
            By corelight        
        A Wireguard VPN protocol analyzer, based on Spicy.        
     
        
        
        
            By corelight        
        A Zeek based STRRAT malware detector.        
     
        
        
        
            By corelight        
        A plugin to find Windows executables that have been XOR encoded.        
     
        
        
        Page 3 of 4, showing 20 record(s) out of 66 total