Packages

zeek-jpeg

By corelight

This package provides some basic analysis for JPEG files.

zeek-kafka

By seisollc

A Zeek log writer plugin that publishes to Kafka.

zeek-known-hosts-with-dns

By dopheide

This script expands the base known-hosts policy to include reverse DNS queries and syncs it across all workers.

zeek-known-outbound

By dopheide

This script provides the ability to monitor and throw notices for outbound connections to a list of watched countries. It also adds orig and resp country codes to conn.log. It depends on having libmaxmind configured for GeoIP lookups.

zeek-log-all-http-headers

By sethhall

Add all HTTP headers and values to the HTTP log.

zeek-long-connections

By corelight

Find and log long-lived connections into a "conn_long" log.

zeek-macho

By corelight

This package provides some basic analysis for Mach-o files.

zeek-netmap

By zeek

Packet source plugin that provides native Netmap support.

zeek-network-statistics

By 0xxon

Perform regular network measurements and report results.

zeek-new-domains

By rvictory

Monitors for new domains being queried for and raises a notice for them

zeek-notice-config

By dopheide

This script enables easy customation of how notice actions are handled. It's built to work with eZeekConfigurator, but that isn't required.

zeek-notice-slack

By pgaulon

Zeek Notices through Slack webhook

zeek-notice-telegram

By corelight

Package that extends the Notice Framework to include `ACTION_TELEGRAM` for sending messages on notices over Telegram.

zeek-ntp-monlist

By dopheide

This script just replaces the old ntp-monlist script to work with Zeek 3.0.0+

zeek-open-connections

By activecm

Find and log open, long-lived connections into a "conn_long" log.

zeek-openvpn

By corelight

A Zeek OpenVPN Protocol Analyzer

zeek-pdf-analyzer

By reservoirlabs

A PDF file analyzer for Zeek

zeek-plugin-bacnet

By amzn

Plugin that enables parsing of the BACnet standard building controls protocol

Page 8 of 9, showing 20 record(s) out of 180 total