mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00
Remove unnecessary #includes in analyzer/packet analyzer/file analyzer headers
This commit is contained in:
parent
896e41c794
commit
456c1fa42c
72 changed files with 41 additions and 91 deletions
|
@ -22,6 +22,8 @@ Discarder::Discarder() {
|
||||||
discarder_maxlen = static_cast<int>(id::find_val("discarder_maxlen")->AsCount());
|
discarder_maxlen = static_cast<int>(id::find_val("discarder_maxlen")->AsCount());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Discarder::~Discarder() {}
|
||||||
|
|
||||||
bool Discarder::IsActive() { return check_ip || check_tcp || check_udp || check_icmp; }
|
bool Discarder::IsActive() { return check_ip || check_tcp || check_udp || check_icmp; }
|
||||||
|
|
||||||
bool Discarder::NextPacket(const std::shared_ptr<IP_Hdr>& ip, int len, int caplen) {
|
bool Discarder::NextPacket(const std::shared_ptr<IP_Hdr>& ip, int len, int caplen) {
|
||||||
|
|
|
@ -19,7 +19,7 @@ namespace detail {
|
||||||
class Discarder final {
|
class Discarder final {
|
||||||
public:
|
public:
|
||||||
Discarder();
|
Discarder();
|
||||||
~Discarder() = default;
|
~Discarder();
|
||||||
|
|
||||||
bool IsActive();
|
bool IsActive();
|
||||||
|
|
||||||
|
|
|
@ -10,7 +10,6 @@
|
||||||
|
|
||||||
#include "zeek/EventHandler.h"
|
#include "zeek/EventHandler.h"
|
||||||
#include "zeek/IntrusivePtr.h"
|
#include "zeek/IntrusivePtr.h"
|
||||||
#include "zeek/Obj.h"
|
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/Timer.h"
|
#include "zeek/Timer.h"
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/zeek-config.h"
|
|
||||||
|
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/plugin/Component.h"
|
#include "zeek/plugin/Component.h"
|
||||||
#include "zeek/util.h"
|
#include "zeek/util.h"
|
||||||
|
|
|
@ -24,10 +24,10 @@
|
||||||
#include <vector>
|
#include <vector>
|
||||||
|
|
||||||
#include "zeek/IP.h"
|
#include "zeek/IP.h"
|
||||||
|
#include "zeek/IPAddr.h"
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/analyzer/Analyzer.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
#include "zeek/analyzer/Component.h"
|
#include "zeek/analyzer/Component.h"
|
||||||
#include "zeek/analyzer/analyzer.bif.h"
|
|
||||||
#include "zeek/net_util.h"
|
#include "zeek/net_util.h"
|
||||||
#include "zeek/plugin/ComponentManager.h"
|
#include "zeek/plugin/ComponentManager.h"
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/NetVar.h"
|
|
||||||
#include "zeek/analyzer/Analyzer.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::conn_size {
|
namespace zeek::analyzer::conn_size {
|
||||||
|
|
|
@ -2,10 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/IPAddr.h"
|
#include "zeek/Conn.h"
|
||||||
#include "zeek/NetVar.h"
|
|
||||||
#include "zeek/analyzer/protocol/dce-rpc/dce_rpc_pac.h"
|
#include "zeek/analyzer/protocol/dce-rpc/dce_rpc_pac.h"
|
||||||
#include "zeek/analyzer/protocol/dce-rpc/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::dce_rpc {
|
namespace zeek::analyzer::dce_rpc {
|
||||||
|
|
|
@ -792,7 +792,7 @@ bool DNS_Interpreter::ParseRR_EDNS(detail::DNS_MsgInfo* msg, const u_char*& data
|
||||||
|
|
||||||
void DNS_Interpreter::ExtractOctets(const u_char*& data, int& len, String** p) {
|
void DNS_Interpreter::ExtractOctets(const u_char*& data, int& len, String** p) {
|
||||||
uint16_t dlen = ExtractShort(data, len);
|
uint16_t dlen = ExtractShort(data, len);
|
||||||
dlen = min(len, static_cast<int>(dlen));
|
dlen = std::min(len, static_cast<int>(dlen));
|
||||||
|
|
||||||
if ( p )
|
if ( p )
|
||||||
*p = new String(data, dlen, false);
|
*p = new String(data, dlen, false);
|
||||||
|
@ -802,8 +802,8 @@ void DNS_Interpreter::ExtractOctets(const u_char*& data, int& len, String** p) {
|
||||||
}
|
}
|
||||||
|
|
||||||
String* DNS_Interpreter::ExtractStream(const u_char*& data, int& len, int l) {
|
String* DNS_Interpreter::ExtractStream(const u_char*& data, int& len, int l) {
|
||||||
l = max(l, 0);
|
l = std::max(l, 0);
|
||||||
int dlen = min(len, l); // Len in bytes of the algorithm use
|
int dlen = std::min(len, l); // Len in bytes of the algorithm use
|
||||||
auto rval = new String(data, dlen, false);
|
auto rval = new String(data, dlen, false);
|
||||||
|
|
||||||
data += dlen;
|
data += dlen;
|
||||||
|
|
|
@ -3,7 +3,6 @@
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
#include "zeek/binpac_zeek.h"
|
|
||||||
|
|
||||||
namespace zeek::analyzer::dns {
|
namespace zeek::analyzer::dns {
|
||||||
namespace detail {
|
namespace detail {
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/gssapi/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/gssapi/gssapi_pac.h"
|
#include "zeek/analyzer/protocol/gssapi/gssapi_pac.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
|
|
|
@ -2,9 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
// for std::transform
|
|
||||||
#include <algorithm>
|
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
#include "analyzer/protocol/imap/imap_pac.h"
|
#include "analyzer/protocol/imap/imap_pac.h"
|
||||||
|
|
|
@ -2,15 +2,15 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
// This is needed for USE_KRB5 below.
|
||||||
#include "zeek/zeek-config.h"
|
#include "zeek/zeek-config.h"
|
||||||
|
|
||||||
#include <mutex>
|
|
||||||
|
|
||||||
#ifdef USE_KRB5
|
#ifdef USE_KRB5
|
||||||
#include <krb5/krb5.h>
|
#include <krb5/krb5.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#include "analyzer/protocol/krb/krb_pac.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
|
#include "zeek/analyzer/protocol/krb/krb_pac.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::krb {
|
namespace zeek::analyzer::krb {
|
||||||
|
|
||||||
|
|
|
@ -4,7 +4,6 @@
|
||||||
|
|
||||||
#include <cassert>
|
#include <cassert>
|
||||||
#include <cstdio>
|
#include <cstdio>
|
||||||
#include <queue>
|
|
||||||
#include <vector>
|
#include <vector>
|
||||||
|
|
||||||
#include "zeek/Reporter.h"
|
#include "zeek/Reporter.h"
|
||||||
|
|
|
@ -4,7 +4,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/ID.h"
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
namespace binpac {
|
namespace binpac {
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/mysql/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/mysql/mysql_pac.h"
|
#include "zeek/analyzer/protocol/mysql/mysql_pac.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
|
|
|
@ -17,7 +17,6 @@
|
||||||
//
|
//
|
||||||
// http://faydoc.tripod.com/structures/21/2149.htm
|
// http://faydoc.tripod.com/structures/21/2149.htm
|
||||||
|
|
||||||
#include "zeek/NetVar.h"
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
#include "analyzer/protocol/ncp/ncp_pac.h"
|
#include "analyzer/protocol/ncp/ncp_pac.h"
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/ntlm/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/ntlm/ntlm_pac.h"
|
#include "zeek/analyzer/protocol/ntlm/ntlm_pac.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
|
|
|
@ -2,9 +2,7 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/ntp/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/ntp/ntp_pac.h"
|
#include "zeek/analyzer/protocol/ntp/ntp_pac.h"
|
||||||
#include "zeek/analyzer/protocol/ntp/types.bif.h"
|
|
||||||
|
|
||||||
namespace zeek::analyzer::ntp {
|
namespace zeek::analyzer::ntp {
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/radius/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/radius/radius_pac.h"
|
#include "zeek/analyzer/protocol/radius/radius_pac.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::radius {
|
namespace zeek::analyzer::radius {
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/rdp/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/rdp/rdp_pac.h"
|
#include "zeek/analyzer/protocol/rdp/rdp_pac.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/rdp/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/rdp/rdpeudp_pac.h"
|
#include "zeek/analyzer/protocol/rdp/rdpeudp_pac.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::rdpeudp {
|
namespace zeek::analyzer::rdpeudp {
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/rfb/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/rfb/rfb_pac.h"
|
#include "zeek/analyzer/protocol/rfb/rfb_pac.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/NetVar.h"
|
|
||||||
#include "zeek/analyzer/protocol/rpc/RPC.h"
|
#include "zeek/analyzer/protocol/rpc/RPC.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::rpc {
|
namespace zeek::analyzer::rpc {
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/NetVar.h"
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::rpc {
|
namespace zeek::analyzer::rpc {
|
||||||
|
|
|
@ -5,8 +5,6 @@
|
||||||
#include <netinet/in.h>
|
#include <netinet/in.h>
|
||||||
#include <sys/types.h>
|
#include <sys/types.h>
|
||||||
|
|
||||||
#include "zeek/util.h"
|
|
||||||
|
|
||||||
namespace zeek::analyzer::rpc {
|
namespace zeek::analyzer::rpc {
|
||||||
|
|
||||||
extern uint32_t extract_XDR_uint32(const u_char*& buf, int& len);
|
extern uint32_t extract_XDR_uint32(const u_char*& buf, int& len);
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/sip/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/sip/sip_pac.h"
|
#include "zeek/analyzer/protocol/sip/sip_pac.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::sip {
|
namespace zeek::analyzer::sip {
|
||||||
|
|
|
@ -2,7 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "analyzer/protocol/snmp/snmp_pac.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
|
#include "zeek/analyzer/protocol/snmp/snmp_pac.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::snmp {
|
namespace zeek::analyzer::snmp {
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
%include zeek.pac
|
%include zeek.pac
|
||||||
|
|
||||||
%extern{
|
%extern{
|
||||||
#include "zeek/Reporter.h"
|
|
||||||
#include "zeek/analyzer/protocol/snmp/types.bif.h"
|
#include "zeek/analyzer/protocol/snmp/types.bif.h"
|
||||||
#include "zeek/analyzer/protocol/snmp/events.bif.h"
|
#include "zeek/analyzer/protocol/snmp/events.bif.h"
|
||||||
%}
|
%}
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/ssh/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/ssh/ssh_pac.h"
|
#include "zeek/analyzer/protocol/ssh/ssh_pac.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,7 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/ssl/events.bif.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
|
|
||||||
namespace binpac {
|
namespace binpac {
|
||||||
namespace DTLS {
|
namespace DTLS {
|
||||||
|
|
|
@ -3,7 +3,6 @@
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/pia/PIA.h"
|
#include "zeek/analyzer/protocol/pia/PIA.h"
|
||||||
#include "zeek/analyzer/protocol/ssl/events.bif.h"
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
||||||
namespace binpac {
|
namespace binpac {
|
||||||
|
|
|
@ -2,7 +2,7 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
|
|
||||||
#include "analyzer/protocol/syslog/legacy/syslog_pac.h"
|
#include "analyzer/protocol/syslog/legacy/syslog_pac.h"
|
||||||
|
|
||||||
|
|
|
@ -3,10 +3,8 @@
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/Conn.h"
|
#include "zeek/Conn.h"
|
||||||
#include "zeek/IPAddr.h"
|
|
||||||
#include "zeek/analyzer/Analyzer.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP_Endpoint.h"
|
#include "zeek/analyzer/protocol/tcp/TCP_Endpoint.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP_Flags.h"
|
|
||||||
#include "zeek/packet_analysis/protocol/tcp/TCPSessionAdapter.h"
|
#include "zeek/packet_analysis/protocol/tcp/TCPSessionAdapter.h"
|
||||||
|
|
||||||
namespace zeek::analyzer::pia {
|
namespace zeek::analyzer::pia {
|
||||||
|
|
|
@ -2,8 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/zeek-config.h"
|
|
||||||
|
|
||||||
#include <zlib.h>
|
#include <zlib.h>
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
#include "zeek/analyzer/protocol/tcp/TCP.h"
|
||||||
|
|
|
@ -2,8 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/zeek-config.h"
|
|
||||||
|
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/plugin/Component.h"
|
#include "zeek/plugin/Component.h"
|
||||||
|
|
||||||
|
|
|
@ -2,21 +2,21 @@
|
||||||
|
|
||||||
#include "zeek/file_analysis/File.h"
|
#include "zeek/file_analysis/File.h"
|
||||||
|
|
||||||
#include <limits>
|
|
||||||
#include <utility>
|
#include <utility>
|
||||||
|
|
||||||
|
#include "zeek/Conn.h"
|
||||||
#include "zeek/Event.h"
|
#include "zeek/Event.h"
|
||||||
#include "zeek/Reporter.h"
|
#include "zeek/Reporter.h"
|
||||||
#include "zeek/RuleMatcher.h"
|
#include "zeek/RuleMatcher.h"
|
||||||
#include "zeek/Type.h"
|
#include "zeek/Type.h"
|
||||||
#include "zeek/Val.h"
|
#include "zeek/Val.h"
|
||||||
#include "zeek/analyzer/Analyzer.h"
|
#include "zeek/analyzer/Analyzer.h"
|
||||||
#include "zeek/analyzer/Manager.h"
|
|
||||||
#include "zeek/file_analysis/Analyzer.h"
|
#include "zeek/file_analysis/Analyzer.h"
|
||||||
#include "zeek/file_analysis/FileReassembler.h"
|
#include "zeek/file_analysis/FileReassembler.h"
|
||||||
#include "zeek/file_analysis/FileTimer.h"
|
#include "zeek/file_analysis/FileTimer.h"
|
||||||
#include "zeek/file_analysis/Manager.h"
|
#include "zeek/file_analysis/Manager.h"
|
||||||
#include "zeek/file_analysis/analyzer/extract/Extract.h"
|
#include "zeek/file_analysis/analyzer/extract/Extract.h"
|
||||||
|
#include "zeek/file_analysis/analyzer/extract/events.bif.h"
|
||||||
|
|
||||||
namespace zeek::file_analysis {
|
namespace zeek::file_analysis {
|
||||||
|
|
||||||
|
|
|
@ -4,12 +4,10 @@
|
||||||
|
|
||||||
#include <list>
|
#include <list>
|
||||||
#include <string>
|
#include <string>
|
||||||
#include <utility>
|
|
||||||
|
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/WeirdState.h"
|
#include "zeek/WeirdState.h"
|
||||||
#include "zeek/ZeekArgs.h"
|
#include "zeek/ZeekArgs.h"
|
||||||
#include "zeek/ZeekList.h" // for ValPList
|
|
||||||
#include "zeek/ZeekString.h"
|
#include "zeek/ZeekString.h"
|
||||||
#include "zeek/file_analysis/AnalyzerSet.h"
|
#include "zeek/file_analysis/AnalyzerSet.h"
|
||||||
|
|
||||||
|
|
|
@ -7,7 +7,6 @@
|
||||||
namespace zeek {
|
namespace zeek {
|
||||||
|
|
||||||
class Connection;
|
class Connection;
|
||||||
class File;
|
|
||||||
|
|
||||||
namespace file_analysis {
|
namespace file_analysis {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include <string>
|
|
||||||
|
|
||||||
#include "zeek/EventHandler.h"
|
#include "zeek/EventHandler.h"
|
||||||
#include "zeek/Val.h"
|
#include "zeek/Val.h"
|
||||||
#include "zeek/file_analysis/Analyzer.h"
|
#include "zeek/file_analysis/Analyzer.h"
|
||||||
|
|
|
@ -6,6 +6,7 @@
|
||||||
|
|
||||||
#include "zeek/Event.h"
|
#include "zeek/Event.h"
|
||||||
#include "zeek/file_analysis/Manager.h"
|
#include "zeek/file_analysis/Manager.h"
|
||||||
|
#include "zeek/file_analysis/analyzer/entropy/events.bif.h"
|
||||||
#include "zeek/util.h"
|
#include "zeek/util.h"
|
||||||
|
|
||||||
namespace zeek::file_analysis::detail {
|
namespace zeek::file_analysis::detail {
|
||||||
|
|
|
@ -2,13 +2,10 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include <string>
|
|
||||||
|
|
||||||
#include "zeek/OpaqueVal.h"
|
#include "zeek/OpaqueVal.h"
|
||||||
#include "zeek/Val.h"
|
#include "zeek/Val.h"
|
||||||
#include "zeek/file_analysis/Analyzer.h"
|
#include "zeek/file_analysis/Analyzer.h"
|
||||||
#include "zeek/file_analysis/File.h"
|
#include "zeek/file_analysis/File.h"
|
||||||
#include "zeek/file_analysis/analyzer/entropy/events.bif.h"
|
|
||||||
|
|
||||||
namespace zeek::file_analysis::detail {
|
namespace zeek::file_analysis::detail {
|
||||||
|
|
||||||
|
|
|
@ -5,8 +5,8 @@
|
||||||
#include <fcntl.h>
|
#include <fcntl.h>
|
||||||
#include <string>
|
#include <string>
|
||||||
|
|
||||||
#include "zeek/Event.h"
|
|
||||||
#include "zeek/file_analysis/Manager.h"
|
#include "zeek/file_analysis/Manager.h"
|
||||||
|
#include "zeek/file_analysis/analyzer/extract/events.bif.h"
|
||||||
#include "zeek/util.h"
|
#include "zeek/util.h"
|
||||||
|
|
||||||
namespace zeek::file_analysis::detail {
|
namespace zeek::file_analysis::detail {
|
||||||
|
|
|
@ -8,7 +8,6 @@
|
||||||
#include "zeek/Val.h"
|
#include "zeek/Val.h"
|
||||||
#include "zeek/file_analysis/Analyzer.h"
|
#include "zeek/file_analysis/Analyzer.h"
|
||||||
#include "zeek/file_analysis/File.h"
|
#include "zeek/file_analysis/File.h"
|
||||||
#include "zeek/file_analysis/analyzer/extract/events.bif.h"
|
|
||||||
|
|
||||||
namespace zeek::file_analysis::detail {
|
namespace zeek::file_analysis::detail {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include <string>
|
|
||||||
|
|
||||||
#include "zeek/OpaqueVal.h"
|
#include "zeek/OpaqueVal.h"
|
||||||
#include "zeek/Val.h"
|
#include "zeek/Val.h"
|
||||||
#include "zeek/file_analysis/Analyzer.h"
|
#include "zeek/file_analysis/Analyzer.h"
|
||||||
|
|
|
@ -2,9 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include <string>
|
|
||||||
|
|
||||||
#include "zeek/File.h"
|
|
||||||
#include "zeek/Val.h"
|
#include "zeek/Val.h"
|
||||||
|
|
||||||
#include "file_analysis/analyzer/pe/pe_pac.h"
|
#include "file_analysis/analyzer/pe/pe_pac.h"
|
||||||
|
|
|
@ -2,8 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/zeek-config.h"
|
|
||||||
|
|
||||||
#include <functional>
|
#include <functional>
|
||||||
|
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
|
|
|
@ -3,7 +3,6 @@
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include <cstdint>
|
#include <cstdint>
|
||||||
#include <map>
|
|
||||||
#include <memory>
|
#include <memory>
|
||||||
#include <vector>
|
#include <vector>
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/Func.h"
|
|
||||||
#include "zeek/PacketFilter.h"
|
#include "zeek/PacketFilter.h"
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/iosource/Packet.h"
|
#include "zeek/iosource/Packet.h"
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::AYIYA {
|
namespace zeek::packet_analysis::AYIYA {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::FDDI {
|
namespace zeek::packet_analysis::FDDI {
|
||||||
|
|
||||||
|
|
|
@ -2,11 +2,12 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include <cstdint>
|
||||||
#include <functional>
|
#include <functional>
|
||||||
|
|
||||||
#include "zeek/Span.h"
|
#include "zeek/Span.h"
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::Geneve {
|
namespace zeek::packet_analysis::Geneve {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::GRE {
|
namespace zeek::packet_analysis::GRE {
|
||||||
|
|
||||||
|
|
|
@ -2,6 +2,7 @@
|
||||||
|
|
||||||
#include "zeek/packet_analysis/protocol/icmp/ICMPSessionAdapter.h"
|
#include "zeek/packet_analysis/protocol/icmp/ICMPSessionAdapter.h"
|
||||||
|
|
||||||
|
#include "zeek/Conn.h"
|
||||||
#include "zeek/analyzer/Manager.h"
|
#include "zeek/analyzer/Manager.h"
|
||||||
#include "zeek/analyzer/protocol/conn-size/ConnSize.h"
|
#include "zeek/analyzer/protocol/conn-size/ConnSize.h"
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::IEEE802_11 {
|
namespace zeek::packet_analysis::IEEE802_11 {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::IEEE802_11_Radio {
|
namespace zeek::packet_analysis::IEEE802_11_Radio {
|
||||||
|
|
||||||
|
|
|
@ -8,7 +8,6 @@
|
||||||
#include "zeek/Event.h"
|
#include "zeek/Event.h"
|
||||||
#include "zeek/Frag.h"
|
#include "zeek/Frag.h"
|
||||||
#include "zeek/IP.h"
|
#include "zeek/IP.h"
|
||||||
#include "zeek/IPAddr.h"
|
|
||||||
#include "zeek/NetVar.h"
|
#include "zeek/NetVar.h"
|
||||||
#include "zeek/PacketFilter.h"
|
#include "zeek/PacketFilter.h"
|
||||||
#include "zeek/RunState.h"
|
#include "zeek/RunState.h"
|
||||||
|
|
|
@ -5,7 +5,6 @@
|
||||||
#include <map>
|
#include <map>
|
||||||
#include <set>
|
#include <set>
|
||||||
|
|
||||||
#include "zeek/ID.h"
|
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,10 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include <cstdint>
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::LinuxSLL2 {
|
namespace zeek::packet_analysis::LinuxSLL2 {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::LLC {
|
namespace zeek::packet_analysis::LLC {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::MPLS {
|
namespace zeek::packet_analysis::MPLS {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::NFLog {
|
namespace zeek::packet_analysis::NFLog {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::Novell_802_3 {
|
namespace zeek::packet_analysis::Novell_802_3 {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::PPP {
|
namespace zeek::packet_analysis::PPP {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::PPPSerial {
|
namespace zeek::packet_analysis::PPPSerial {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::PPPoE {
|
namespace zeek::packet_analysis::PPPoE {
|
||||||
|
|
||||||
|
|
|
@ -2,7 +2,6 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP_Flags.h"
|
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
#include "zeek/packet_analysis/Component.h"
|
||||||
#include "zeek/packet_analysis/protocol/ip/IPBasedAnalyzer.h"
|
#include "zeek/packet_analysis/protocol/ip/IPBasedAnalyzer.h"
|
||||||
|
|
|
@ -5,8 +5,6 @@
|
||||||
#include "zeek/Tag.h"
|
#include "zeek/Tag.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP_Endpoint.h"
|
#include "zeek/analyzer/protocol/tcp/TCP_Endpoint.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP_Flags.h"
|
#include "zeek/analyzer/protocol/tcp/TCP_Flags.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
#include "zeek/packet_analysis/protocol/ip/SessionAdapter.h"
|
#include "zeek/packet_analysis/protocol/ip/SessionAdapter.h"
|
||||||
#include "zeek/session/Manager.h"
|
#include "zeek/session/Manager.h"
|
||||||
|
|
||||||
|
|
|
@ -5,7 +5,6 @@
|
||||||
#include <map>
|
#include <map>
|
||||||
|
|
||||||
#include "zeek/Conn.h"
|
#include "zeek/Conn.h"
|
||||||
#include "zeek/NetVar.h"
|
|
||||||
#include "zeek/RE.h"
|
#include "zeek/RE.h"
|
||||||
#include "zeek/Reporter.h"
|
#include "zeek/Reporter.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::VNTag {
|
namespace zeek::packet_analysis::VNTag {
|
||||||
|
|
||||||
|
|
|
@ -2,8 +2,8 @@
|
||||||
|
|
||||||
#pragma once
|
#pragma once
|
||||||
|
|
||||||
|
#include "zeek/iosource/Packet.h"
|
||||||
#include "zeek/packet_analysis/Analyzer.h"
|
#include "zeek/packet_analysis/Analyzer.h"
|
||||||
#include "zeek/packet_analysis/Component.h"
|
|
||||||
|
|
||||||
namespace zeek::packet_analysis::VXLAN {
|
namespace zeek::packet_analysis::VXLAN {
|
||||||
|
|
||||||
|
|
|
@ -24,6 +24,7 @@
|
||||||
|
|
||||||
#include <hilti/autogen/config.h>
|
#include <hilti/autogen/config.h>
|
||||||
|
|
||||||
|
#include "zeek/Event.h"
|
||||||
#include "zeek/analyzer/Manager.h"
|
#include "zeek/analyzer/Manager.h"
|
||||||
#include "zeek/file_analysis/Manager.h"
|
#include "zeek/file_analysis/Manager.h"
|
||||||
#include "zeek/packet_analysis/Manager.h"
|
#include "zeek/packet_analysis/Manager.h"
|
||||||
|
|
|
@ -2,6 +2,7 @@
|
||||||
#include "Foo.h"
|
#include "Foo.h"
|
||||||
|
|
||||||
#include "zeek/EventRegistry.h"
|
#include "zeek/EventRegistry.h"
|
||||||
|
#include "zeek/Func.h"
|
||||||
#include "zeek/analyzer/protocol/tcp/TCP_Reassembler.h"
|
#include "zeek/analyzer/protocol/tcp/TCP_Reassembler.h"
|
||||||
|
|
||||||
#include "events.bif.h"
|
#include "events.bif.h"
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue