By cisagov
ATT&CK-based Control-system Indicator Detection (ACID) is a collection of Zeek scripts designed to detect ATT&CK for ICS behaviors on OT protocols. These events are reported through the Zeek Notice framework.
By corelight
A package to detect CVE-2021-42292, a Microsoft Excel priviledge exploit.
By sithari
Detects exfiltration of data over ICMP and writes to notice.log with the details of the exfil like duration, exfil size, source/dest ip, etc.
Page 1 of 1, showing 10 record(s) out of 10 total