Packages
By reshadp
Add MAC address to all logs.
By corelight
Find and log long-lived connections into a "conn_long" log.
By corelight
This package provides some basic analysis for Mach-o files.
By corelight
Package that extends the Notice Framework to include
`ACTION_TELEGRAM` for sending messages on notices over Telegram.
By activecm
Find and log open, long-lived connections into a "conn_long" log.
By corelight
Detects the Google QUIC (GQUIC) protocol and adds "gquic"
to conn.log's "service" field.
By corelight
A Facefish rootkit detector, based on Spicy.
By corelight
An IPSec Zeek protocol analyzer based on Spicy.
By corelight
A Zeek OpenVPN protocol analyzer, based on Spicy.
By corelight
A Zeek OSPF packet analyzer, based on Spicy.
By corelight
A Zeek STUN protocol analyzer based on Spicy.
By corelight
A Wireguard VPN protocol analyzer, based on Spicy.
By corelight
A plugin to find Windows executables that have been XOR encoded.
By corelight
Experimental JavaScript support for Zeek.
By pgaulon
Package extending the Notice Framework to include to send Notices via Slack webhooks.
By corelight
Package that extends the Notice Framework to include
`ACTION_TELEGRAM` for sending messages on notices over Telegram using ZeekJS.
By corelight
Detects Zerologon (CVE-2020-1472) attempts and exploits.
Page 3 of 3, showing 18 record(s) out of 58 total