Detect DoH servers by adding a is_DoH field in ssl.log and add timeout to them so that the DoH connection won't take too long
This script gets the gateway IP information taken from the dhcp logs, and adds a notice.log entry if the gateway address is identified
By nttcom
TODO: A more detailed description of test. It can span multiple lines, with this indentation.
By amzn
Plugin that enables parsing of the BACnet standard building controls protocol
By amzn
Plugin that enables parsing of the Ethernet/IP and Common Industrial Protocol standards
By corelight
Detects the Google QUIC (GQUIC) protocol and adds "gquic" to conn.log's "service" field.
By cybera
Sniffpass will alert on cleartext passwords discovered in HTTP POST requests
By dopheide
This script replaces the default ssh/interesting-hostnames and reduces the number of asyncrhonous when() calls made by Zeek.