mirror of
https://github.com/zeek/zeek.git
synced 2025-10-09 18:18:19 +00:00
Some script reorg and a new intel extension script.
- policy/frameworks/intel/seen is the new location for the scripts that push data into the intel framework for checking. - The new policy/frameworks/intel/do_notice script adds an example mechanism for data driven notices.
This commit is contained in:
parent
d380161244
commit
32f1c736f7
15 changed files with 67 additions and 24 deletions
|
@ -1,12 +0,0 @@
|
|||
@load base/frameworks/intel
|
||||
@load base/protocols/http/utils
|
||||
@load ./where-locations
|
||||
|
||||
event http_message_done(c: connection, is_orig: bool, stat: http_message_stat)
|
||||
{
|
||||
if ( is_orig && c?$http )
|
||||
Intel::seen([$indicator=HTTP::build_url(c$http),
|
||||
$indicator_type=Intel::URL,
|
||||
$conn=c,
|
||||
$where=HTTP::IN_URL]);
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue