Packages

zeek-jpeg

By corelight

This package provides some basic analysis for JPEG files.

zeek-kafka

By seisollc

A Zeek log writer plugin that publishes to Kafka.

zeek-known-hosts-with-dns

By dopheide

This script expands the base known-hosts policy to include reverse DNS queries and syncs it across all workers.

zeek-known-outbound

By dopheide

This script provides the ability to monitor and throw notices for outbound connections to a list of watched countries. It also adds orig and resp country codes to conn.log. It depends on having libmaxmind configured for GeoIP lookups.

Zeek-Known-Services-With-OrigFlag

By esnet-security

This script expands the base known-services policy to include is_local_orig flag to indicate if the service was discovered from non-local nets (is_local_orig =F) or from local nets (is_local_orig=T).

zeek-log-add-mac-addresses

By reshadp

Add MAC address to all logs.

zeek-log-all-http-headers

By sethhall

Add all HTTP headers and values to the HTTP log.

zeek-log-writer-nats

By corelight

NATS.io log writer support

zeek-long-connections

By corelight

Find and log long-lived connections into a "conn_long" log.

zeek-macho

By corelight

This package provides some basic analysis for Mach-o files.

zeek-matchy-plugin

By matchylabs

High-performance threat intelligence matching for Zeek using Matchy databases. Drop-in alternative to the Intel Framework with shared-memory databases and automatic hot-reload.

zeek-mercury-npf

By corelight

TODO: A more detailed description of Mercury. It can span multiple lines, with this indentation.

zeek-more-hashes

By zeek

Additional hashing functions for Zeek, started with MurmurHash3.

zeek-netmap

By zeek

Packet source plugin that provides native Netmap support.

zeek-netsupport-detector

By corelight

A Zeek base NetSupport detector. NetSupport is often abused by attackers in malware.

zeek-network-statistics

By 0xxon

Perform regular network measurements and report results.

zeek-new-domains

By rvictory

Monitors for new domains being queried for and raises a notice for them

zeek-njrat-detector

By keithjjones

A Zeek based njRAT detector.

zeek-notice-config

By dopheide

This script enables easy customation of how notice actions are handled. It's built to work with eZeekConfigurator, but that isn't required.

Page 11 of 15, showing 20 record(s) out of 281 total