Packages

dns_axfr

By srozb

Find and notice DNS zone transfer attempts.

dns-tunnels

By hhzzk

Detect DNS Tunnels attack.

domain-tld

By sethhall

A library for getting the "effective tld" of a domain name.

dovehawk

By dovehawk

MISP+Bro. Dovehawk is a Bro Module to import MISP indicators to the Intel Framework automatically and report sightings directly back to MISP as they happen.

dummy-connections

By hosom

Create dummy connection records.

file-extraction

By hosom

Extract files from network traffic with Bro.

find_smbv1

By klehigh

find SMBv1 activity

fix-ascii

By reservoirlabs

ASCII FIX analyzer package

fix-binary

By reservoirlabs

binary FIX analyzer package

flow_labels

By bricata

Provides mechanisms for managing and using institutional knowledge about a monitored environment to make informed observations of normal and abnormal network activity.

ftp-bruteforce

By initconf

ftp-bruteforce

hassh

By salesforce

HASSH is used to identify specific Client and Server SSH implementations. The fingerprints can be stored, searched and shared in the form of an MD5 fingerprint. This package logs components to ssh.log

http_csp

By srozb

HTTP Content-Security-Policy report parser

http-stalling-detector

By corelight

Detect HTTP stalling attacks like slowloris.

intel-extensions

By j-gras

Extensions for Bro's intelligence framework.

intel-seen-more

By j-gras

Additional seen-triggers for Bro's intelligence framework.

ja3

By salesforce

JA3 creates 32 character SSL client fingerprints and logs them as a field in ssl.log. These fingerprints can easily be shared as threat intelligence or used as correlation items for enhanced alerting and analysis. This package also adds JA3 to the Bro Intel Framework. https://github.com/salesforce/ja3

Joe-Sandbox-Bro

By joesecurity

JoeSandbox-Bro extracts files from your internet connection and analyzes them automatically on Joe Sandbox. Combined with Joe Sandbox's reporting and alerting features you can build a powerful IDS.

json-streaming-logs

By corelight

JSON streaming logs

ldap-analyzer

By scebro

LDAP write operations analyzer for Bro.

Page 3 of 4, showing 20 record(s) out of 79 total