By cisagov
ATT&CK-based Control-system Indicator Detection (ACID) is a collection of Zeek scripts designed to detect ATT&CK for ICS behaviors on OT protocols. These events are reported through the Zeek Notice framework.
By jbaggs
A module for tracking and correlating abnormal DNS behavior. Detection of tunneling and C&C through connection duration and volume, request and answer size, DNS request type, and unique queries per domain. Statistical classification of fast flux networks based on A records and ASNs.
By stevesmoot
Leverage nDPI and other info to make informed guess at the application for a connection.
By amarokinc
Adds ASN reputation data of external IP addresses to notice.log if the ASN crosses a predetermined threshold as defined by circl.lu
By dopheide
Adds support for multi-notice correlation. For more information, see http://blog.samoehlert.com/correlating-bro-notices or the talk from BroCon 2016.
By ncsa
A broctl plugin that helps you troubleshoot common problems For cluster-related checks, the package "add-node-names" is recommended.