A module for tracking and correlating abnormal DNS behavior. Detection of tunneling and C&C through connection duration and volume, request and answer size, DNS request type, and unique queries per domain. Statistical clasification of fast flux networks based on A records and ASNs.
Leverage nDPI and other info to make informed guess at the application for a connection.
Packet source plugin that provides native Myricom SNF v3+v4 support.
Detect credit card numbers in HTTP and SMTP with Bro.
A library for getting the "effective tld" of a domain name.
Additional seen-triggers for Bro's intelligence framework.
Detect US Social Security numbers in HTTP and SMTP.
Log the top DNS queries being requested.
Help Zeek by finding unidentified file types.
Add all HTTP headers and values to the HTTP log.
Monitors for new domains being queried for and raises a notice for them
Page 1 of 1, showing 11 record(s) out of 11 total