Packages

zeek-package-ARP

By stratosphereips

Zeek Package that supports adding arp.log to zeek log files

zeek-package-detect-DoH

By stratosphereips

Detect DoH servers by adding a is_DoH field in ssl.log and add timeout to them so that the DoH connection won't take too long

zeek-package-IRC

By stratosphereips

Zeek Package that extracts features of IRC communication

zeek-package-log-gateway-IP

By stratosphereips

This script gets the gateway IP information taken from the dhcp logs, and adds a notice.log entry if the gateway address is identified

zeek-parser-Bacnet

By nttcom

TODO: A more detailed description of icsnpp-bacnet. It can span multiple lines, with this indentation.

zeek-parser-CCLinkField-CCLinkControl

By nttcom

TODO: A more detailed description of spicy_cc_link_noip. It can span multiple lines, with this indentation.

zeek-parser-CCLinkFieldBasic

By nttcom

TODO: A more detailed description of spicy_cc_link_basic. It can span multiple lines, with this indentation.

zeek-parser-CIFS-COM

By nttcom

TODO: A more detailed description of test. It can span multiple lines, with this indentation.

zeek-parser-CIFS-NBNS-COM

By nttcom

TODO: A more detailed description of zeek-parser-NBNS. It can span multiple lines, with this indentation.

zeek-parser-DHCPv4-COM

By nttcom

TODO: A more detailed description of zeek-parser-DHCPv4-COM. It can span multiple lines, with this indentation.

zeek-parser-DHCPv6-COM

By nttcom

TODO: A more detailed description of zeek-parser-DHCPV6. It can span multiple lines, with this indentation.

zeek-parser-SSDP-COM

By nttcom

TODO: A more detailed description of zeek-parser-SSDP. It can span multiple lines, with this indentation.

zeek-pcapovertcp-plugin

By emnahum

Provides PCAP over TCP support for Zeek.

zeek-plugin-bacnet

By amzn

Plugin that enables parsing of the BACnet standard building controls protocol

zeek-plugin-enip

By amzn

Plugin that enables parsing of the Ethernet/IP and Common Industrial Protocol standards

zeek-plugin-ikev2

By ukncsc

Plugin that enables parsing of the IKEv2 protocol

zeek-plugin-profinet

By amzn

Plugin that enables parsing of the Profinet protocol

zeek-plugin-roca

By 0xxon

Identify certificates potentially affected by CVE-2017-15361

zeek-plugin-s7comm

By amzn

Plugin that enables parsing of the S7 protocol

zeek-plugin-tds

By amzn

Plugin that enables parsing of the Tabular Data Stream (TDS) protocol

Page 11 of 13, showing 20 record(s) out of 242 total