threat intel questions

Ambros Novak <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAHifxyA177h2+TEQ7r1wprVYOZceSX11kWiLV-NeOiWnG3MOCA@mail.gmail.com>
Hello!

I have several questions about the threat intel:

Is there a way to add meta.url and meta.desc to intel.log?

For Intel::FILE_NAME to work, does base/frameworks/intel/files.bro go in
local.bro?

Will Intel::FILE_HASH detect MD5, SHA1, SHA256, SHA256, imphash, and
authentihash?

Will Intel::CERT_HASH detect MD5 or SHA256?

Will the intel frame detect part of part a URL or does only the full URL?

Will "@domain.com" work in the Intel::EMAIL, or is it best to just remove
the "@" and add it to Intel::Domain?

Does meta.do_notice have to be set to T for an event to get logged into
intel.log?

Thank you for the help.

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.