Packages

add-json

By j-gras

Additional JSON-logging for Bro.

add-node-names

By j-gras

Adds cluster node name to logs.

blacklist

By initconf

package to manage blacklisted IP address ysing bro

bro_bitcoin

By jsiwek

Detects Bitcoin, Litecoin, or other cryptocurrency mining traffic that uses getwork, getblocktemplate, or Stratum mining protocols over TCP or HTTP.

bro_notice_correlation

By dopheide

Adds support for multi-notice correlation. For more information, see http://blog.samoehlert.com/correlating-bro-notices or the talk from BroCon 2016.

bro-af_packet-plugin

By j-gras

This plugin provides native AF_Packet support for Bro.

bro-community-id

By corelight

"Community ID" flow hash support in conn.log

bro-dag

By endace

Packet source plugin that provides native support for Endace DAG capture cards.

bro-doctor

By ncsa

A broctl plugin that helps you troubleshoot common problems

bro-drwatson

By corelight

Discover and log information discovered in Microsoft DrWatson messages.

bro-fuzzy-hashing

By j-gras

This plugin provides fuzzy hashing for Bro.

bro-hardware

By corelight

Scripts for cases where hardware device identifiers are discovered.

bro-http2

By mitrecnd

A HTTP2 protocol analyzer for the Bro IDS.

bro-interface-setup

By ncsa

A broctl plugin that helps you setup capture interfaces

bro-inventory-scripts

By fatemabw

Find different type of OSes and AV software in your network traffic.

bro-is-darknet

By ncsa

This plugin adds a Site::is_darknet function. This is useful for scripts that track scan attempts or other probes. It can handle purely dark address space as well as honeynet space.

bro-ja3

By hosom

Generate and log ja3 ssl fingerprints

bro-large_uploads

By theflakes

Raise notices on outgoing files over X bytes in size. Also raise notices for multiple large outgoing Tx's in Y time frame.

bro-lognorm

By j-gras

This plugin provides liblognorm integration for Bro.

bro-long-connections

By corelight

Find and log long-lived connections into a "conn_long" log.

Page 1 of 4, showing 20 record(s) out of 79 total