Packages

zeek-intel-path

By captainGeech42

Extend Intel framework to alert on URL paths

zeek-jemalloc-profiling

By justinazoff

A broctl plugin that enables jemalloc profiling

zeek-jetdirect

By dopheide

Detect exploit attempt of HP JetDirect printers

zeek-jpeg

By corelight

This package provides some basic analysis for JPEG files.

zeek-kafka

By seisollc

A Zeek log writer plugin that publishes to Kafka.

zeek-known-hosts-with-dns

By dopheide

This script expands the base known-hosts policy to include reverse DNS queries and syncs it across all workers.

zeek-known-outbound

By dopheide

This script provides the ability to monitor and throw notices for outbound connections to a list of watched countries. It also adds orig and resp country codes to conn.log. It depends on having libmaxmind configured for GeoIP lookups.

zeek-log-all-http-headers

By sethhall

Add all HTTP headers and values to the HTTP log.

zeek-long-connections

By corelight

Find and log long-lived connections into a "conn_long" log.

zeek-macho

By corelight

This package provides some basic analysis for Mach-o files.

zeek-netmap

By zeek

Packet source plugin that provides native Netmap support.

zeek-network-statistics

By 0xxon

Perform regular network measurements and report results.

zeek-new-domains

By rvictory

Monitors for new domains being queried for and raises a notice for them

zeek-notice-config

By dopheide

This script enables easy customation of how notice actions are handled. It's built to work with eZeekConfigurator, but that isn't required.

zeek-notice-slack

By pgaulon

Zeek Notices through Slack webhook

zeek-notice-telegram

By corelight

Package that extends the Notice Framework to include `ACTION_TELEGRAM` for sending messages on notices over Telegram.

zeek-ntp-monlist

By dopheide

This script just replaces the old ntp-monlist script to work with Zeek 3.0.0+

zeek-open-connections

By activecm

Find and log open, long-lived connections into a "conn_long" log.

zeek-openvpn

By corelight

A Zeek OpenVPN Protocol Analyzer

Page 9 of 11, showing 20 record(s) out of 207 total