threat intel questions
Ambros Novak <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAHifxyA177h2+TEQ7r1wprVYOZceSX11kWiLV-NeOiWnG3MOCA@mail.gmail.com> |
Hello! I have several questions about the threat intel: Is there a way to add meta.url and meta.desc to intel.log? For Intel::FILE_NAME to work, does base/frameworks/intel/files.bro go in local.bro? Will Intel::FILE_HASH detect MD5, SHA1, SHA256, SHA256, imphash, and authentihash? Will Intel::CERT_HASH detect MD5 or SHA256? Will the intel frame detect part of part a URL or does only the full URL? Will "@domain.com" work in the Intel::EMAIL, or is it best to just remove the "@" and add it to Intel::Domain? Does meta.do_notice have to be set to T for an event to get logged into intel.log? Thank you for the help. _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek