mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
Normalize the intel seen filename for smb.
This commit is contained in:
parent
2d3a21968e
commit
1d5eac4ee1
1 changed files with 3 additions and 1 deletions
|
@ -11,7 +11,9 @@ event file_new(f: fa_file)
|
|||
local c = f$conns[id];
|
||||
if ( c?$smb_state && c$smb_state?$current_file && c$smb_state$current_file?$name )
|
||||
{
|
||||
Intel::seen([$indicator=c$smb_state$current_file$name,
|
||||
local split_fname = split_string(c$smb_state$current_file$name, /\\/);
|
||||
local fname = split_fname[|split_fname|-1];
|
||||
Intel::seen([$indicator=fname,
|
||||
$indicator_type=Intel::FILE_NAME,
|
||||
$f=f,
|
||||
$where=SMB::IN_FILE_NAME]);
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue