mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
Update tests and baselines due to renaming all scripts
This commit is contained in:
parent
18bd74454b
commit
4e0c1997a0
33 changed files with 635 additions and 635 deletions
|
@ -1,4 +1,4 @@
|
||||||
loaded lcl2.base.utils.site.bro
|
loaded lcl2.base.utils.site.zeek
|
||||||
loaded lcl.base.utils.site.bro
|
loaded lcl.base.utils.site.zeek
|
||||||
loaded lcl2.base.protocols.http.bro
|
loaded lcl2.base.protocols.http.bro
|
||||||
loaded lcl.base.protocols.http.zeek
|
loaded lcl.base.protocols.http.zeek
|
||||||
|
|
|
@ -1,3 +1,3 @@
|
||||||
fatal error in /home/robin/bro/master/scripts/base/frameworks/packet-filter/./main.bro, line 282: Bad pcap filter 'kaputt'
|
fatal error in /home/robin/bro/master/scripts/base/frameworks/packet-filter/./main.zeek, line 282: Bad pcap filter 'kaputt'
|
||||||
----
|
----
|
||||||
error, cannot compile BPF filter "kaputt, too"
|
error, cannot compile BPF filter "kaputt, too"
|
||||||
|
|
|
@ -6,177 +6,177 @@
|
||||||
#open 2018-06-08-16-37-15
|
#open 2018-06-08-16-37-15
|
||||||
#fields name
|
#fields name
|
||||||
#types string
|
#types string
|
||||||
scripts/base/init-bare.bro
|
scripts/base/init-bare.zeek
|
||||||
build/scripts/base/bif/const.bif.bro
|
build/scripts/base/bif/const.bif.zeek
|
||||||
build/scripts/base/bif/types.bif.bro
|
build/scripts/base/bif/types.bif.zeek
|
||||||
build/scripts/base/bif/bro.bif.bro
|
build/scripts/base/bif/bro.bif.zeek
|
||||||
build/scripts/base/bif/stats.bif.bro
|
build/scripts/base/bif/stats.bif.zeek
|
||||||
build/scripts/base/bif/reporter.bif.bro
|
build/scripts/base/bif/reporter.bif.zeek
|
||||||
build/scripts/base/bif/strings.bif.bro
|
build/scripts/base/bif/strings.bif.zeek
|
||||||
build/scripts/base/bif/option.bif.bro
|
build/scripts/base/bif/option.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SNMP.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SNMP.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_KRB.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_KRB.types.bif.zeek
|
||||||
build/scripts/base/bif/event.bif.bro
|
build/scripts/base/bif/event.bif.zeek
|
||||||
scripts/base/init-frameworks-and-bifs.bro
|
scripts/base/init-frameworks-and-bifs.zeek
|
||||||
scripts/base/frameworks/logging/__load__.bro
|
scripts/base/frameworks/logging/__load__.zeek
|
||||||
scripts/base/frameworks/logging/main.bro
|
scripts/base/frameworks/logging/main.zeek
|
||||||
build/scripts/base/bif/logging.bif.bro
|
build/scripts/base/bif/logging.bif.zeek
|
||||||
scripts/base/frameworks/logging/postprocessors/__load__.bro
|
scripts/base/frameworks/logging/postprocessors/__load__.zeek
|
||||||
scripts/base/frameworks/logging/postprocessors/scp.bro
|
scripts/base/frameworks/logging/postprocessors/scp.zeek
|
||||||
scripts/base/frameworks/logging/postprocessors/sftp.bro
|
scripts/base/frameworks/logging/postprocessors/sftp.zeek
|
||||||
scripts/base/frameworks/logging/writers/ascii.bro
|
scripts/base/frameworks/logging/writers/ascii.zeek
|
||||||
scripts/base/frameworks/logging/writers/sqlite.bro
|
scripts/base/frameworks/logging/writers/sqlite.zeek
|
||||||
scripts/base/frameworks/logging/writers/none.bro
|
scripts/base/frameworks/logging/writers/none.zeek
|
||||||
scripts/base/frameworks/broker/__load__.bro
|
scripts/base/frameworks/broker/__load__.zeek
|
||||||
scripts/base/frameworks/broker/main.bro
|
scripts/base/frameworks/broker/main.zeek
|
||||||
build/scripts/base/bif/comm.bif.bro
|
build/scripts/base/bif/comm.bif.zeek
|
||||||
build/scripts/base/bif/messaging.bif.bro
|
build/scripts/base/bif/messaging.bif.zeek
|
||||||
scripts/base/frameworks/broker/store.bro
|
scripts/base/frameworks/broker/store.zeek
|
||||||
build/scripts/base/bif/data.bif.bro
|
build/scripts/base/bif/data.bif.zeek
|
||||||
build/scripts/base/bif/store.bif.bro
|
build/scripts/base/bif/store.bif.zeek
|
||||||
scripts/base/frameworks/broker/log.bro
|
scripts/base/frameworks/broker/log.zeek
|
||||||
scripts/base/frameworks/input/__load__.bro
|
scripts/base/frameworks/input/__load__.zeek
|
||||||
scripts/base/frameworks/input/main.bro
|
scripts/base/frameworks/input/main.zeek
|
||||||
build/scripts/base/bif/input.bif.bro
|
build/scripts/base/bif/input.bif.zeek
|
||||||
scripts/base/frameworks/input/readers/ascii.bro
|
scripts/base/frameworks/input/readers/ascii.zeek
|
||||||
scripts/base/frameworks/input/readers/raw.bro
|
scripts/base/frameworks/input/readers/raw.zeek
|
||||||
scripts/base/frameworks/input/readers/benchmark.bro
|
scripts/base/frameworks/input/readers/benchmark.zeek
|
||||||
scripts/base/frameworks/input/readers/binary.bro
|
scripts/base/frameworks/input/readers/binary.zeek
|
||||||
scripts/base/frameworks/input/readers/config.bro
|
scripts/base/frameworks/input/readers/config.zeek
|
||||||
scripts/base/frameworks/input/readers/sqlite.bro
|
scripts/base/frameworks/input/readers/sqlite.zeek
|
||||||
scripts/base/frameworks/analyzer/__load__.bro
|
scripts/base/frameworks/analyzer/__load__.zeek
|
||||||
scripts/base/frameworks/analyzer/main.bro
|
scripts/base/frameworks/analyzer/main.zeek
|
||||||
scripts/base/frameworks/packet-filter/utils.bro
|
scripts/base/frameworks/packet-filter/utils.zeek
|
||||||
build/scripts/base/bif/analyzer.bif.bro
|
build/scripts/base/bif/analyzer.bif.zeek
|
||||||
scripts/base/frameworks/files/__load__.bro
|
scripts/base/frameworks/files/__load__.zeek
|
||||||
scripts/base/frameworks/files/main.bro
|
scripts/base/frameworks/files/main.zeek
|
||||||
build/scripts/base/bif/file_analysis.bif.bro
|
build/scripts/base/bif/file_analysis.bif.zeek
|
||||||
scripts/base/utils/site.bro
|
scripts/base/utils/site.zeek
|
||||||
scripts/base/utils/patterns.bro
|
scripts/base/utils/patterns.zeek
|
||||||
scripts/base/frameworks/files/magic/__load__.bro
|
scripts/base/frameworks/files/magic/__load__.zeek
|
||||||
build/scripts/base/bif/__load__.bro
|
build/scripts/base/bif/__load__.zeek
|
||||||
build/scripts/base/bif/broxygen.bif.bro
|
build/scripts/base/bif/broxygen.bif.zeek
|
||||||
build/scripts/base/bif/pcap.bif.bro
|
build/scripts/base/bif/pcap.bif.zeek
|
||||||
build/scripts/base/bif/bloom-filter.bif.bro
|
build/scripts/base/bif/bloom-filter.bif.zeek
|
||||||
build/scripts/base/bif/cardinality-counter.bif.bro
|
build/scripts/base/bif/cardinality-counter.bif.zeek
|
||||||
build/scripts/base/bif/top-k.bif.bro
|
build/scripts/base/bif/top-k.bif.zeek
|
||||||
build/scripts/base/bif/plugins/__load__.bro
|
build/scripts/base/bif/plugins/__load__.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ARP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_ARP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BackDoor.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_BackDoor.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BitTorrent.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_BitTorrent.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ConnSize.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_ConnSize.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ConnSize.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_ConnSize.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DCE_RPC.consts.bif.bro
|
build/scripts/base/bif/plugins/Bro_DCE_RPC.consts.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DCE_RPC.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_DCE_RPC.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DCE_RPC.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DCE_RPC.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DHCP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DHCP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DHCP.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_DHCP.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DNP3.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DNP3.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DNS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DNS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_File.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_File.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Finger.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Finger.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FTP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_FTP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Gnutella.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Gnutella.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_GSSAPI.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_GSSAPI.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_GTPv1.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_GTPv1.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_HTTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_HTTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_HTTP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_HTTP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ICMP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_ICMP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Ident.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Ident.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_IMAP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_IMAP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_InterConn.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_InterConn.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_IRC.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_IRC.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_KRB.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_KRB.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Login.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Login.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Login.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_Login.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_MIME.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_MIME.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Modbus.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Modbus.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_MySQL.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_MySQL.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NCP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NCP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NCP.consts.bif.bro
|
build/scripts/base/bif/plugins/Bro_NCP.consts.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NetBIOS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NetBIOS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NetBIOS.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_NetBIOS.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NTLM.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_NTLM.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NTLM.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NTLM.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_POP3.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_POP3.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RADIUS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RADIUS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RDP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RDP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RDP.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_RDP.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RFB.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RFB.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RPC.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RPC.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SIP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SIP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SNMP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SNMP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_check_directory.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_check_directory.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_close.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_close.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_create_directory.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_create_directory.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_echo.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_echo.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_logoff_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_logoff_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_negotiate.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_negotiate.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_create_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_create_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_cancel.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_cancel.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_query_information.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_query_information.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_read_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_read_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_session_setup_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_session_setup_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction_secondary.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction_secondary.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2_secondary.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2_secondary.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_connect_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_connect_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_disconnect.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_disconnect.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_write_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_write_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_close.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_close.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_create.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_create.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_negotiate.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_negotiate.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_read.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_read.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_session_setup.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_session_setup.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_set_info.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_set_info.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_connect.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_connect.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_disconnect.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_disconnect.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_write.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_write.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_transform_header.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_transform_header.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.consts.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.consts.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMTP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMTP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SOCKS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SOCKS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSH.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSH.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSH.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSH.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSL.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSL.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSL.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSL.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSL.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSL.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SteppingStone.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SteppingStone.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Syslog.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Syslog.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_TCP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_TCP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_TCP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_TCP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Teredo.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Teredo.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_UDP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_UDP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_VXLAN.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_VXLAN.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_XMPP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_XMPP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileEntropy.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileEntropy.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileExtract.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileExtract.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileExtract.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileExtract.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileHash.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileHash.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_PE.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_PE.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Unified2.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Unified2.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Unified2.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_Unified2.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.ocsp_events.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.ocsp_events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_AsciiReader.ascii.bif.bro
|
build/scripts/base/bif/plugins/Bro_AsciiReader.ascii.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BenchmarkReader.benchmark.bif.bro
|
build/scripts/base/bif/plugins/Bro_BenchmarkReader.benchmark.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BinaryReader.binary.bif.bro
|
build/scripts/base/bif/plugins/Bro_BinaryReader.binary.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ConfigReader.config.bif.bro
|
build/scripts/base/bif/plugins/Bro_ConfigReader.config.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RawReader.raw.bif.bro
|
build/scripts/base/bif/plugins/Bro_RawReader.raw.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SQLiteReader.sqlite.bif.bro
|
build/scripts/base/bif/plugins/Bro_SQLiteReader.sqlite.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_AsciiWriter.ascii.bif.bro
|
build/scripts/base/bif/plugins/Bro_AsciiWriter.ascii.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NoneWriter.none.bif.bro
|
build/scripts/base/bif/plugins/Bro_NoneWriter.none.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SQLiteWriter.sqlite.bif.bro
|
build/scripts/base/bif/plugins/Bro_SQLiteWriter.sqlite.bif.zeek
|
||||||
scripts/policy/misc/loaded-scripts.bro
|
scripts/policy/misc/loaded-scripts.zeek
|
||||||
scripts/base/utils/paths.bro
|
scripts/base/utils/paths.zeek
|
||||||
#close 2018-06-08-16-37-15
|
#close 2018-06-08-16-37-15
|
||||||
|
|
|
@ -1,18 +1,18 @@
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 245: deprecated (dhcp_discover)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 245: deprecated (dhcp_discover)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 248: deprecated (dhcp_offer)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 248: deprecated (dhcp_offer)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 251: deprecated (dhcp_request)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 251: deprecated (dhcp_request)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 254: deprecated (dhcp_decline)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 254: deprecated (dhcp_decline)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 257: deprecated (dhcp_ack)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 257: deprecated (dhcp_ack)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 260: deprecated (dhcp_nak)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 260: deprecated (dhcp_nak)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 263: deprecated (dhcp_release)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 263: deprecated (dhcp_release)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 266: deprecated (dhcp_inform)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 266: deprecated (dhcp_inform)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /Users/jon/projects/bro/bro/testing/btest/../../scripts//broxygen/__load__.bro:10 "Use '@load base/protocols/smb' instead"
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/smb/__load__.zeek, line 1: deprecated script loaded from /Users/jon/projects/bro/bro/testing/btest/../../scripts//broxygen/__load__.zeek:10 "Use '@load base/protocols/smb' instead"
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 245: deprecated (dhcp_discover)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 245: deprecated (dhcp_discover)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 248: deprecated (dhcp_offer)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 248: deprecated (dhcp_offer)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 251: deprecated (dhcp_request)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 251: deprecated (dhcp_request)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 254: deprecated (dhcp_decline)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 254: deprecated (dhcp_decline)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 257: deprecated (dhcp_ack)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 257: deprecated (dhcp_ack)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 260: deprecated (dhcp_nak)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 260: deprecated (dhcp_nak)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 263: deprecated (dhcp_release)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 263: deprecated (dhcp_release)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.bro, line 266: deprecated (dhcp_inform)
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/dhcp/deprecated_events.zeek, line 266: deprecated (dhcp_inform)
|
||||||
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from command line arguments "Use '@load base/protocols/smb' instead"
|
warning in /Users/jon/projects/bro/bro/testing/btest/../../scripts//policy/protocols/smb/__load__.zeek, line 1: deprecated script loaded from command line arguments "Use '@load base/protocols/smb' instead"
|
||||||
|
|
|
@ -6,371 +6,371 @@
|
||||||
#open 2018-09-05-20-33-08
|
#open 2018-09-05-20-33-08
|
||||||
#fields name
|
#fields name
|
||||||
#types string
|
#types string
|
||||||
scripts/base/init-bare.bro
|
scripts/base/init-bare.zeek
|
||||||
build/scripts/base/bif/const.bif.bro
|
build/scripts/base/bif/const.bif.zeek
|
||||||
build/scripts/base/bif/types.bif.bro
|
build/scripts/base/bif/types.bif.zeek
|
||||||
build/scripts/base/bif/bro.bif.bro
|
build/scripts/base/bif/bro.bif.zeek
|
||||||
build/scripts/base/bif/stats.bif.bro
|
build/scripts/base/bif/stats.bif.zeek
|
||||||
build/scripts/base/bif/reporter.bif.bro
|
build/scripts/base/bif/reporter.bif.zeek
|
||||||
build/scripts/base/bif/strings.bif.bro
|
build/scripts/base/bif/strings.bif.zeek
|
||||||
build/scripts/base/bif/option.bif.bro
|
build/scripts/base/bif/option.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SNMP.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SNMP.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_KRB.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_KRB.types.bif.zeek
|
||||||
build/scripts/base/bif/event.bif.bro
|
build/scripts/base/bif/event.bif.zeek
|
||||||
scripts/base/init-frameworks-and-bifs.bro
|
scripts/base/init-frameworks-and-bifs.zeek
|
||||||
scripts/base/frameworks/logging/__load__.bro
|
scripts/base/frameworks/logging/__load__.zeek
|
||||||
scripts/base/frameworks/logging/main.bro
|
scripts/base/frameworks/logging/main.zeek
|
||||||
build/scripts/base/bif/logging.bif.bro
|
build/scripts/base/bif/logging.bif.zeek
|
||||||
scripts/base/frameworks/logging/postprocessors/__load__.bro
|
scripts/base/frameworks/logging/postprocessors/__load__.zeek
|
||||||
scripts/base/frameworks/logging/postprocessors/scp.bro
|
scripts/base/frameworks/logging/postprocessors/scp.zeek
|
||||||
scripts/base/frameworks/logging/postprocessors/sftp.bro
|
scripts/base/frameworks/logging/postprocessors/sftp.zeek
|
||||||
scripts/base/frameworks/logging/writers/ascii.bro
|
scripts/base/frameworks/logging/writers/ascii.zeek
|
||||||
scripts/base/frameworks/logging/writers/sqlite.bro
|
scripts/base/frameworks/logging/writers/sqlite.zeek
|
||||||
scripts/base/frameworks/logging/writers/none.bro
|
scripts/base/frameworks/logging/writers/none.zeek
|
||||||
scripts/base/frameworks/broker/__load__.bro
|
scripts/base/frameworks/broker/__load__.zeek
|
||||||
scripts/base/frameworks/broker/main.bro
|
scripts/base/frameworks/broker/main.zeek
|
||||||
build/scripts/base/bif/comm.bif.bro
|
build/scripts/base/bif/comm.bif.zeek
|
||||||
build/scripts/base/bif/messaging.bif.bro
|
build/scripts/base/bif/messaging.bif.zeek
|
||||||
scripts/base/frameworks/broker/store.bro
|
scripts/base/frameworks/broker/store.zeek
|
||||||
build/scripts/base/bif/data.bif.bro
|
build/scripts/base/bif/data.bif.zeek
|
||||||
build/scripts/base/bif/store.bif.bro
|
build/scripts/base/bif/store.bif.zeek
|
||||||
scripts/base/frameworks/broker/log.bro
|
scripts/base/frameworks/broker/log.zeek
|
||||||
scripts/base/frameworks/input/__load__.bro
|
scripts/base/frameworks/input/__load__.zeek
|
||||||
scripts/base/frameworks/input/main.bro
|
scripts/base/frameworks/input/main.zeek
|
||||||
build/scripts/base/bif/input.bif.bro
|
build/scripts/base/bif/input.bif.zeek
|
||||||
scripts/base/frameworks/input/readers/ascii.bro
|
scripts/base/frameworks/input/readers/ascii.zeek
|
||||||
scripts/base/frameworks/input/readers/raw.bro
|
scripts/base/frameworks/input/readers/raw.zeek
|
||||||
scripts/base/frameworks/input/readers/benchmark.bro
|
scripts/base/frameworks/input/readers/benchmark.zeek
|
||||||
scripts/base/frameworks/input/readers/binary.bro
|
scripts/base/frameworks/input/readers/binary.zeek
|
||||||
scripts/base/frameworks/input/readers/config.bro
|
scripts/base/frameworks/input/readers/config.zeek
|
||||||
scripts/base/frameworks/input/readers/sqlite.bro
|
scripts/base/frameworks/input/readers/sqlite.zeek
|
||||||
scripts/base/frameworks/analyzer/__load__.bro
|
scripts/base/frameworks/analyzer/__load__.zeek
|
||||||
scripts/base/frameworks/analyzer/main.bro
|
scripts/base/frameworks/analyzer/main.zeek
|
||||||
scripts/base/frameworks/packet-filter/utils.bro
|
scripts/base/frameworks/packet-filter/utils.zeek
|
||||||
build/scripts/base/bif/analyzer.bif.bro
|
build/scripts/base/bif/analyzer.bif.zeek
|
||||||
scripts/base/frameworks/files/__load__.bro
|
scripts/base/frameworks/files/__load__.zeek
|
||||||
scripts/base/frameworks/files/main.bro
|
scripts/base/frameworks/files/main.zeek
|
||||||
build/scripts/base/bif/file_analysis.bif.bro
|
build/scripts/base/bif/file_analysis.bif.zeek
|
||||||
scripts/base/utils/site.bro
|
scripts/base/utils/site.zeek
|
||||||
scripts/base/utils/patterns.bro
|
scripts/base/utils/patterns.zeek
|
||||||
scripts/base/frameworks/files/magic/__load__.bro
|
scripts/base/frameworks/files/magic/__load__.zeek
|
||||||
build/scripts/base/bif/__load__.bro
|
build/scripts/base/bif/__load__.zeek
|
||||||
build/scripts/base/bif/broxygen.bif.bro
|
build/scripts/base/bif/broxygen.bif.zeek
|
||||||
build/scripts/base/bif/pcap.bif.bro
|
build/scripts/base/bif/pcap.bif.zeek
|
||||||
build/scripts/base/bif/bloom-filter.bif.bro
|
build/scripts/base/bif/bloom-filter.bif.zeek
|
||||||
build/scripts/base/bif/cardinality-counter.bif.bro
|
build/scripts/base/bif/cardinality-counter.bif.zeek
|
||||||
build/scripts/base/bif/top-k.bif.bro
|
build/scripts/base/bif/top-k.bif.zeek
|
||||||
build/scripts/base/bif/plugins/__load__.bro
|
build/scripts/base/bif/plugins/__load__.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ARP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_ARP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BackDoor.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_BackDoor.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BitTorrent.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_BitTorrent.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ConnSize.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_ConnSize.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ConnSize.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_ConnSize.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DCE_RPC.consts.bif.bro
|
build/scripts/base/bif/plugins/Bro_DCE_RPC.consts.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DCE_RPC.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_DCE_RPC.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DCE_RPC.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DCE_RPC.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DHCP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DHCP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DHCP.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_DHCP.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DNP3.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DNP3.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_DNS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_DNS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_File.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_File.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Finger.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Finger.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FTP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_FTP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Gnutella.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Gnutella.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_GSSAPI.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_GSSAPI.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_GTPv1.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_GTPv1.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_HTTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_HTTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_HTTP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_HTTP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ICMP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_ICMP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Ident.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Ident.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_IMAP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_IMAP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_InterConn.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_InterConn.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_IRC.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_IRC.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_KRB.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_KRB.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Login.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Login.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Login.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_Login.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_MIME.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_MIME.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Modbus.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Modbus.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_MySQL.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_MySQL.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NCP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NCP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NCP.consts.bif.bro
|
build/scripts/base/bif/plugins/Bro_NCP.consts.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NetBIOS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NetBIOS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NetBIOS.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_NetBIOS.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NTLM.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_NTLM.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NTLM.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NTLM.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_NTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_POP3.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_POP3.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RADIUS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RADIUS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RDP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RDP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RDP.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_RDP.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RFB.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RFB.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RPC.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_RPC.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SIP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SIP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SNMP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SNMP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_check_directory.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_check_directory.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_close.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_close.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_create_directory.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_create_directory.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_echo.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_echo.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_logoff_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_logoff_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_negotiate.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_negotiate.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_create_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_create_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_cancel.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_nt_cancel.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_query_information.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_query_information.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_read_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_read_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_session_setup_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_session_setup_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction_secondary.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction_secondary.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2_secondary.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_transaction2_secondary.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_connect_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_connect_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_disconnect.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_tree_disconnect.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_write_andx.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_com_write_andx.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb1_events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb1_events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_close.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_close.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_create.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_create.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_negotiate.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_negotiate.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_read.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_read.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_session_setup.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_session_setup.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_set_info.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_set_info.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_connect.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_connect.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_disconnect.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_tree_disconnect.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_write.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_write.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_transform_header.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_com_transform_header.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.smb2_events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.smb2_events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.consts.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.consts.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMB.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMB.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMTP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMTP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SMTP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_SMTP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SOCKS.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SOCKS.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSH.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSH.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSH.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSH.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSL.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSL.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSL.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSL.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SSL.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_SSL.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SteppingStone.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_SteppingStone.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Syslog.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Syslog.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_TCP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_TCP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_TCP.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_TCP.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Teredo.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Teredo.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_UDP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_UDP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_VXLAN.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_VXLAN.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_XMPP.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_XMPP.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileEntropy.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileEntropy.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileExtract.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileExtract.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileExtract.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileExtract.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_FileHash.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_FileHash.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_PE.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_PE.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Unified2.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_Unified2.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_Unified2.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_Unified2.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.events.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.types.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.types.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.functions.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.functions.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_X509.ocsp_events.bif.bro
|
build/scripts/base/bif/plugins/Bro_X509.ocsp_events.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_AsciiReader.ascii.bif.bro
|
build/scripts/base/bif/plugins/Bro_AsciiReader.ascii.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BenchmarkReader.benchmark.bif.bro
|
build/scripts/base/bif/plugins/Bro_BenchmarkReader.benchmark.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_BinaryReader.binary.bif.bro
|
build/scripts/base/bif/plugins/Bro_BinaryReader.binary.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_ConfigReader.config.bif.bro
|
build/scripts/base/bif/plugins/Bro_ConfigReader.config.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_RawReader.raw.bif.bro
|
build/scripts/base/bif/plugins/Bro_RawReader.raw.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SQLiteReader.sqlite.bif.bro
|
build/scripts/base/bif/plugins/Bro_SQLiteReader.sqlite.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_AsciiWriter.ascii.bif.bro
|
build/scripts/base/bif/plugins/Bro_AsciiWriter.ascii.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_NoneWriter.none.bif.bro
|
build/scripts/base/bif/plugins/Bro_NoneWriter.none.bif.zeek
|
||||||
build/scripts/base/bif/plugins/Bro_SQLiteWriter.sqlite.bif.bro
|
build/scripts/base/bif/plugins/Bro_SQLiteWriter.sqlite.bif.zeek
|
||||||
scripts/base/init-default.bro
|
scripts/base/init-default.zeek
|
||||||
scripts/base/utils/active-http.bro
|
scripts/base/utils/active-http.zeek
|
||||||
scripts/base/utils/exec.bro
|
scripts/base/utils/exec.zeek
|
||||||
scripts/base/utils/addrs.bro
|
scripts/base/utils/addrs.zeek
|
||||||
scripts/base/utils/conn-ids.bro
|
scripts/base/utils/conn-ids.zeek
|
||||||
scripts/base/utils/dir.bro
|
scripts/base/utils/dir.zeek
|
||||||
scripts/base/frameworks/reporter/__load__.bro
|
scripts/base/frameworks/reporter/__load__.zeek
|
||||||
scripts/base/frameworks/reporter/main.bro
|
scripts/base/frameworks/reporter/main.zeek
|
||||||
scripts/base/utils/paths.bro
|
scripts/base/utils/paths.zeek
|
||||||
scripts/base/utils/directions-and-hosts.bro
|
scripts/base/utils/directions-and-hosts.zeek
|
||||||
scripts/base/utils/email.bro
|
scripts/base/utils/email.zeek
|
||||||
scripts/base/utils/files.bro
|
scripts/base/utils/files.zeek
|
||||||
scripts/base/utils/geoip-distance.bro
|
scripts/base/utils/geoip-distance.zeek
|
||||||
scripts/base/utils/hash_hrw.bro
|
scripts/base/utils/hash_hrw.zeek
|
||||||
scripts/base/utils/numbers.bro
|
scripts/base/utils/numbers.zeek
|
||||||
scripts/base/utils/queue.bro
|
scripts/base/utils/queue.zeek
|
||||||
scripts/base/utils/strings.bro
|
scripts/base/utils/strings.zeek
|
||||||
scripts/base/utils/thresholds.bro
|
scripts/base/utils/thresholds.zeek
|
||||||
scripts/base/utils/time.bro
|
scripts/base/utils/time.zeek
|
||||||
scripts/base/utils/urls.bro
|
scripts/base/utils/urls.zeek
|
||||||
scripts/base/frameworks/notice/__load__.bro
|
scripts/base/frameworks/notice/__load__.zeek
|
||||||
scripts/base/frameworks/notice/main.bro
|
scripts/base/frameworks/notice/main.zeek
|
||||||
scripts/base/frameworks/cluster/__load__.bro
|
scripts/base/frameworks/cluster/__load__.zeek
|
||||||
scripts/base/frameworks/cluster/main.bro
|
scripts/base/frameworks/cluster/main.zeek
|
||||||
scripts/base/frameworks/control/__load__.bro
|
scripts/base/frameworks/control/__load__.zeek
|
||||||
scripts/base/frameworks/control/main.bro
|
scripts/base/frameworks/control/main.zeek
|
||||||
scripts/base/frameworks/cluster/pools.bro
|
scripts/base/frameworks/cluster/pools.zeek
|
||||||
scripts/base/frameworks/notice/weird.bro
|
scripts/base/frameworks/notice/weird.zeek
|
||||||
scripts/base/frameworks/notice/actions/drop.bro
|
scripts/base/frameworks/notice/actions/drop.zeek
|
||||||
scripts/base/frameworks/netcontrol/__load__.bro
|
scripts/base/frameworks/netcontrol/__load__.zeek
|
||||||
scripts/base/frameworks/netcontrol/types.bro
|
scripts/base/frameworks/netcontrol/types.zeek
|
||||||
scripts/base/frameworks/netcontrol/main.bro
|
scripts/base/frameworks/netcontrol/main.zeek
|
||||||
scripts/base/frameworks/netcontrol/plugin.bro
|
scripts/base/frameworks/netcontrol/plugin.zeek
|
||||||
scripts/base/frameworks/netcontrol/plugins/__load__.bro
|
scripts/base/frameworks/netcontrol/plugins/__load__.zeek
|
||||||
scripts/base/frameworks/netcontrol/plugins/debug.bro
|
scripts/base/frameworks/netcontrol/plugins/debug.zeek
|
||||||
scripts/base/frameworks/netcontrol/plugins/openflow.bro
|
scripts/base/frameworks/netcontrol/plugins/openflow.zeek
|
||||||
scripts/base/frameworks/openflow/__load__.bro
|
scripts/base/frameworks/openflow/__load__.zeek
|
||||||
scripts/base/frameworks/openflow/consts.bro
|
scripts/base/frameworks/openflow/consts.zeek
|
||||||
scripts/base/frameworks/openflow/types.bro
|
scripts/base/frameworks/openflow/types.zeek
|
||||||
scripts/base/frameworks/openflow/main.bro
|
scripts/base/frameworks/openflow/main.zeek
|
||||||
scripts/base/frameworks/openflow/plugins/__load__.bro
|
scripts/base/frameworks/openflow/plugins/__load__.zeek
|
||||||
scripts/base/frameworks/openflow/plugins/ryu.bro
|
scripts/base/frameworks/openflow/plugins/ryu.zeek
|
||||||
scripts/base/utils/json.bro
|
scripts/base/utils/json.zeek
|
||||||
scripts/base/frameworks/openflow/plugins/log.bro
|
scripts/base/frameworks/openflow/plugins/log.zeek
|
||||||
scripts/base/frameworks/openflow/plugins/broker.bro
|
scripts/base/frameworks/openflow/plugins/broker.zeek
|
||||||
scripts/base/frameworks/openflow/non-cluster.bro
|
scripts/base/frameworks/openflow/non-cluster.zeek
|
||||||
scripts/base/frameworks/netcontrol/plugins/packetfilter.bro
|
scripts/base/frameworks/netcontrol/plugins/packetfilter.zeek
|
||||||
scripts/base/frameworks/netcontrol/plugins/broker.bro
|
scripts/base/frameworks/netcontrol/plugins/broker.zeek
|
||||||
scripts/base/frameworks/netcontrol/plugins/acld.bro
|
scripts/base/frameworks/netcontrol/plugins/acld.zeek
|
||||||
scripts/base/frameworks/netcontrol/drop.bro
|
scripts/base/frameworks/netcontrol/drop.zeek
|
||||||
scripts/base/frameworks/netcontrol/shunt.bro
|
scripts/base/frameworks/netcontrol/shunt.zeek
|
||||||
scripts/base/frameworks/netcontrol/catch-and-release.bro
|
scripts/base/frameworks/netcontrol/catch-and-release.zeek
|
||||||
scripts/base/frameworks/netcontrol/non-cluster.bro
|
scripts/base/frameworks/netcontrol/non-cluster.zeek
|
||||||
scripts/base/frameworks/notice/actions/email_admin.bro
|
scripts/base/frameworks/notice/actions/email_admin.zeek
|
||||||
scripts/base/frameworks/notice/actions/page.bro
|
scripts/base/frameworks/notice/actions/page.zeek
|
||||||
scripts/base/frameworks/notice/actions/add-geodata.bro
|
scripts/base/frameworks/notice/actions/add-geodata.zeek
|
||||||
scripts/base/frameworks/notice/actions/pp-alarms.bro
|
scripts/base/frameworks/notice/actions/pp-alarms.zeek
|
||||||
scripts/base/frameworks/dpd/__load__.bro
|
scripts/base/frameworks/dpd/__load__.zeek
|
||||||
scripts/base/frameworks/dpd/main.bro
|
scripts/base/frameworks/dpd/main.zeek
|
||||||
scripts/base/frameworks/signatures/__load__.bro
|
scripts/base/frameworks/signatures/__load__.zeek
|
||||||
scripts/base/frameworks/signatures/main.bro
|
scripts/base/frameworks/signatures/main.zeek
|
||||||
scripts/base/frameworks/packet-filter/__load__.bro
|
scripts/base/frameworks/packet-filter/__load__.zeek
|
||||||
scripts/base/frameworks/packet-filter/main.bro
|
scripts/base/frameworks/packet-filter/main.zeek
|
||||||
scripts/base/frameworks/packet-filter/netstats.bro
|
scripts/base/frameworks/packet-filter/netstats.zeek
|
||||||
scripts/base/frameworks/software/__load__.bro
|
scripts/base/frameworks/software/__load__.zeek
|
||||||
scripts/base/frameworks/software/main.bro
|
scripts/base/frameworks/software/main.zeek
|
||||||
scripts/base/frameworks/intel/__load__.bro
|
scripts/base/frameworks/intel/__load__.zeek
|
||||||
scripts/base/frameworks/intel/main.bro
|
scripts/base/frameworks/intel/main.zeek
|
||||||
scripts/base/frameworks/intel/files.bro
|
scripts/base/frameworks/intel/files.zeek
|
||||||
scripts/base/frameworks/intel/input.bro
|
scripts/base/frameworks/intel/input.zeek
|
||||||
scripts/base/frameworks/config/__load__.bro
|
scripts/base/frameworks/config/__load__.zeek
|
||||||
scripts/base/frameworks/config/main.bro
|
scripts/base/frameworks/config/main.zeek
|
||||||
scripts/base/frameworks/config/input.bro
|
scripts/base/frameworks/config/input.zeek
|
||||||
scripts/base/frameworks/config/weird.bro
|
scripts/base/frameworks/config/weird.zeek
|
||||||
scripts/base/frameworks/sumstats/__load__.bro
|
scripts/base/frameworks/sumstats/__load__.zeek
|
||||||
scripts/base/frameworks/sumstats/main.bro
|
scripts/base/frameworks/sumstats/main.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/__load__.bro
|
scripts/base/frameworks/sumstats/plugins/__load__.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/average.bro
|
scripts/base/frameworks/sumstats/plugins/average.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/hll_unique.bro
|
scripts/base/frameworks/sumstats/plugins/hll_unique.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/last.bro
|
scripts/base/frameworks/sumstats/plugins/last.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/max.bro
|
scripts/base/frameworks/sumstats/plugins/max.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/min.bro
|
scripts/base/frameworks/sumstats/plugins/min.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/sample.bro
|
scripts/base/frameworks/sumstats/plugins/sample.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/std-dev.bro
|
scripts/base/frameworks/sumstats/plugins/std-dev.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/variance.bro
|
scripts/base/frameworks/sumstats/plugins/variance.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/sum.bro
|
scripts/base/frameworks/sumstats/plugins/sum.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/topk.bro
|
scripts/base/frameworks/sumstats/plugins/topk.zeek
|
||||||
scripts/base/frameworks/sumstats/plugins/unique.bro
|
scripts/base/frameworks/sumstats/plugins/unique.zeek
|
||||||
scripts/base/frameworks/sumstats/non-cluster.bro
|
scripts/base/frameworks/sumstats/non-cluster.zeek
|
||||||
scripts/base/frameworks/tunnels/__load__.bro
|
scripts/base/frameworks/tunnels/__load__.zeek
|
||||||
scripts/base/frameworks/tunnels/main.bro
|
scripts/base/frameworks/tunnels/main.zeek
|
||||||
scripts/base/protocols/conn/__load__.bro
|
scripts/base/protocols/conn/__load__.zeek
|
||||||
scripts/base/protocols/conn/main.bro
|
scripts/base/protocols/conn/main.zeek
|
||||||
scripts/base/protocols/conn/contents.bro
|
scripts/base/protocols/conn/contents.zeek
|
||||||
scripts/base/protocols/conn/inactivity.bro
|
scripts/base/protocols/conn/inactivity.zeek
|
||||||
scripts/base/protocols/conn/polling.bro
|
scripts/base/protocols/conn/polling.zeek
|
||||||
scripts/base/protocols/conn/thresholds.bro
|
scripts/base/protocols/conn/thresholds.zeek
|
||||||
scripts/base/protocols/dce-rpc/__load__.bro
|
scripts/base/protocols/dce-rpc/__load__.zeek
|
||||||
scripts/base/protocols/dce-rpc/consts.bro
|
scripts/base/protocols/dce-rpc/consts.zeek
|
||||||
scripts/base/protocols/dce-rpc/main.bro
|
scripts/base/protocols/dce-rpc/main.zeek
|
||||||
scripts/base/protocols/dhcp/__load__.bro
|
scripts/base/protocols/dhcp/__load__.zeek
|
||||||
scripts/base/protocols/dhcp/consts.bro
|
scripts/base/protocols/dhcp/consts.zeek
|
||||||
scripts/base/protocols/dhcp/main.bro
|
scripts/base/protocols/dhcp/main.zeek
|
||||||
scripts/base/protocols/dnp3/__load__.bro
|
scripts/base/protocols/dnp3/__load__.zeek
|
||||||
scripts/base/protocols/dnp3/main.bro
|
scripts/base/protocols/dnp3/main.zeek
|
||||||
scripts/base/protocols/dnp3/consts.bro
|
scripts/base/protocols/dnp3/consts.zeek
|
||||||
scripts/base/protocols/dns/__load__.bro
|
scripts/base/protocols/dns/__load__.zeek
|
||||||
scripts/base/protocols/dns/consts.bro
|
scripts/base/protocols/dns/consts.zeek
|
||||||
scripts/base/protocols/dns/main.bro
|
scripts/base/protocols/dns/main.zeek
|
||||||
scripts/base/protocols/ftp/__load__.bro
|
scripts/base/protocols/ftp/__load__.zeek
|
||||||
scripts/base/protocols/ftp/utils-commands.bro
|
scripts/base/protocols/ftp/utils-commands.zeek
|
||||||
scripts/base/protocols/ftp/info.bro
|
scripts/base/protocols/ftp/info.zeek
|
||||||
scripts/base/protocols/ftp/main.bro
|
scripts/base/protocols/ftp/main.zeek
|
||||||
scripts/base/protocols/ftp/utils.bro
|
scripts/base/protocols/ftp/utils.zeek
|
||||||
scripts/base/protocols/ftp/files.bro
|
scripts/base/protocols/ftp/files.zeek
|
||||||
scripts/base/protocols/ftp/gridftp.bro
|
scripts/base/protocols/ftp/gridftp.zeek
|
||||||
scripts/base/protocols/ssl/__load__.bro
|
scripts/base/protocols/ssl/__load__.zeek
|
||||||
scripts/base/protocols/ssl/consts.bro
|
scripts/base/protocols/ssl/consts.zeek
|
||||||
scripts/base/protocols/ssl/main.bro
|
scripts/base/protocols/ssl/main.zeek
|
||||||
scripts/base/protocols/ssl/mozilla-ca-list.bro
|
scripts/base/protocols/ssl/mozilla-ca-list.zeek
|
||||||
scripts/base/protocols/ssl/ct-list.bro
|
scripts/base/protocols/ssl/ct-list.zeek
|
||||||
scripts/base/protocols/ssl/files.bro
|
scripts/base/protocols/ssl/files.zeek
|
||||||
scripts/base/files/x509/__load__.bro
|
scripts/base/files/x509/__load__.zeek
|
||||||
scripts/base/files/x509/main.bro
|
scripts/base/files/x509/main.zeek
|
||||||
scripts/base/files/hash/__load__.bro
|
scripts/base/files/hash/__load__.zeek
|
||||||
scripts/base/files/hash/main.bro
|
scripts/base/files/hash/main.zeek
|
||||||
scripts/base/protocols/http/__load__.bro
|
scripts/base/protocols/http/__load__.zeek
|
||||||
scripts/base/protocols/http/main.bro
|
scripts/base/protocols/http/main.zeek
|
||||||
scripts/base/protocols/http/entities.bro
|
scripts/base/protocols/http/entities.zeek
|
||||||
scripts/base/protocols/http/utils.bro
|
scripts/base/protocols/http/utils.zeek
|
||||||
scripts/base/protocols/http/files.bro
|
scripts/base/protocols/http/files.zeek
|
||||||
scripts/base/protocols/imap/__load__.bro
|
scripts/base/protocols/imap/__load__.zeek
|
||||||
scripts/base/protocols/imap/main.bro
|
scripts/base/protocols/imap/main.zeek
|
||||||
scripts/base/protocols/irc/__load__.bro
|
scripts/base/protocols/irc/__load__.zeek
|
||||||
scripts/base/protocols/irc/main.bro
|
scripts/base/protocols/irc/main.zeek
|
||||||
scripts/base/protocols/irc/dcc-send.bro
|
scripts/base/protocols/irc/dcc-send.zeek
|
||||||
scripts/base/protocols/irc/files.bro
|
scripts/base/protocols/irc/files.zeek
|
||||||
scripts/base/protocols/krb/__load__.bro
|
scripts/base/protocols/krb/__load__.zeek
|
||||||
scripts/base/protocols/krb/main.bro
|
scripts/base/protocols/krb/main.zeek
|
||||||
scripts/base/protocols/krb/consts.bro
|
scripts/base/protocols/krb/consts.zeek
|
||||||
scripts/base/protocols/krb/files.bro
|
scripts/base/protocols/krb/files.zeek
|
||||||
scripts/base/protocols/modbus/__load__.bro
|
scripts/base/protocols/modbus/__load__.zeek
|
||||||
scripts/base/protocols/modbus/consts.bro
|
scripts/base/protocols/modbus/consts.zeek
|
||||||
scripts/base/protocols/modbus/main.bro
|
scripts/base/protocols/modbus/main.zeek
|
||||||
scripts/base/protocols/mysql/__load__.bro
|
scripts/base/protocols/mysql/__load__.zeek
|
||||||
scripts/base/protocols/mysql/main.bro
|
scripts/base/protocols/mysql/main.zeek
|
||||||
scripts/base/protocols/mysql/consts.bro
|
scripts/base/protocols/mysql/consts.zeek
|
||||||
scripts/base/protocols/ntlm/__load__.bro
|
scripts/base/protocols/ntlm/__load__.zeek
|
||||||
scripts/base/protocols/ntlm/main.bro
|
scripts/base/protocols/ntlm/main.zeek
|
||||||
scripts/base/protocols/pop3/__load__.bro
|
scripts/base/protocols/pop3/__load__.zeek
|
||||||
scripts/base/protocols/radius/__load__.bro
|
scripts/base/protocols/radius/__load__.zeek
|
||||||
scripts/base/protocols/radius/main.bro
|
scripts/base/protocols/radius/main.zeek
|
||||||
scripts/base/protocols/radius/consts.bro
|
scripts/base/protocols/radius/consts.zeek
|
||||||
scripts/base/protocols/rdp/__load__.bro
|
scripts/base/protocols/rdp/__load__.zeek
|
||||||
scripts/base/protocols/rdp/consts.bro
|
scripts/base/protocols/rdp/consts.zeek
|
||||||
scripts/base/protocols/rdp/main.bro
|
scripts/base/protocols/rdp/main.zeek
|
||||||
scripts/base/protocols/rfb/__load__.bro
|
scripts/base/protocols/rfb/__load__.zeek
|
||||||
scripts/base/protocols/rfb/main.bro
|
scripts/base/protocols/rfb/main.zeek
|
||||||
scripts/base/protocols/sip/__load__.bro
|
scripts/base/protocols/sip/__load__.zeek
|
||||||
scripts/base/protocols/sip/main.bro
|
scripts/base/protocols/sip/main.zeek
|
||||||
scripts/base/protocols/snmp/__load__.bro
|
scripts/base/protocols/snmp/__load__.zeek
|
||||||
scripts/base/protocols/snmp/main.bro
|
scripts/base/protocols/snmp/main.zeek
|
||||||
scripts/base/protocols/smb/__load__.bro
|
scripts/base/protocols/smb/__load__.zeek
|
||||||
scripts/base/protocols/smb/consts.bro
|
scripts/base/protocols/smb/consts.zeek
|
||||||
scripts/base/protocols/smb/const-dos-error.bro
|
scripts/base/protocols/smb/const-dos-error.zeek
|
||||||
scripts/base/protocols/smb/const-nt-status.bro
|
scripts/base/protocols/smb/const-nt-status.zeek
|
||||||
scripts/base/protocols/smb/main.bro
|
scripts/base/protocols/smb/main.zeek
|
||||||
scripts/base/protocols/smb/smb1-main.bro
|
scripts/base/protocols/smb/smb1-main.zeek
|
||||||
scripts/base/protocols/smb/smb2-main.bro
|
scripts/base/protocols/smb/smb2-main.zeek
|
||||||
scripts/base/protocols/smb/files.bro
|
scripts/base/protocols/smb/files.zeek
|
||||||
scripts/base/protocols/smtp/__load__.bro
|
scripts/base/protocols/smtp/__load__.zeek
|
||||||
scripts/base/protocols/smtp/main.bro
|
scripts/base/protocols/smtp/main.zeek
|
||||||
scripts/base/protocols/smtp/entities.bro
|
scripts/base/protocols/smtp/entities.zeek
|
||||||
scripts/base/protocols/smtp/files.bro
|
scripts/base/protocols/smtp/files.zeek
|
||||||
scripts/base/protocols/socks/__load__.bro
|
scripts/base/protocols/socks/__load__.zeek
|
||||||
scripts/base/protocols/socks/consts.bro
|
scripts/base/protocols/socks/consts.zeek
|
||||||
scripts/base/protocols/socks/main.bro
|
scripts/base/protocols/socks/main.zeek
|
||||||
scripts/base/protocols/ssh/__load__.bro
|
scripts/base/protocols/ssh/__load__.zeek
|
||||||
scripts/base/protocols/ssh/main.bro
|
scripts/base/protocols/ssh/main.zeek
|
||||||
scripts/base/protocols/syslog/__load__.bro
|
scripts/base/protocols/syslog/__load__.zeek
|
||||||
scripts/base/protocols/syslog/consts.bro
|
scripts/base/protocols/syslog/consts.zeek
|
||||||
scripts/base/protocols/syslog/main.bro
|
scripts/base/protocols/syslog/main.zeek
|
||||||
scripts/base/protocols/tunnels/__load__.bro
|
scripts/base/protocols/tunnels/__load__.zeek
|
||||||
scripts/base/protocols/xmpp/__load__.bro
|
scripts/base/protocols/xmpp/__load__.zeek
|
||||||
scripts/base/protocols/xmpp/main.bro
|
scripts/base/protocols/xmpp/main.zeek
|
||||||
scripts/base/files/pe/__load__.bro
|
scripts/base/files/pe/__load__.zeek
|
||||||
scripts/base/files/pe/consts.bro
|
scripts/base/files/pe/consts.zeek
|
||||||
scripts/base/files/pe/main.bro
|
scripts/base/files/pe/main.zeek
|
||||||
scripts/base/files/extract/__load__.bro
|
scripts/base/files/extract/__load__.zeek
|
||||||
scripts/base/files/extract/main.bro
|
scripts/base/files/extract/main.zeek
|
||||||
scripts/base/files/unified2/__load__.bro
|
scripts/base/files/unified2/__load__.zeek
|
||||||
scripts/base/files/unified2/main.bro
|
scripts/base/files/unified2/main.zeek
|
||||||
scripts/base/misc/find-checksum-offloading.bro
|
scripts/base/misc/find-checksum-offloading.zeek
|
||||||
scripts/base/misc/find-filtered-trace.bro
|
scripts/base/misc/find-filtered-trace.zeek
|
||||||
scripts/base/misc/version.bro
|
scripts/base/misc/version.zeek
|
||||||
scripts/policy/misc/loaded-scripts.bro
|
scripts/policy/misc/loaded-scripts.zeek
|
||||||
#close 2018-09-05-20-33-08
|
#close 2018-09-05-20-33-08
|
||||||
|
|
|
@ -1,10 +1,10 @@
|
||||||
-./frameworks/cluster/nodes/logger.bro
|
-./frameworks/cluster/nodes/logger.zeek
|
||||||
-./frameworks/cluster/nodes/manager.bro
|
-./frameworks/cluster/nodes/manager.zeek
|
||||||
-./frameworks/cluster/nodes/proxy.bro
|
-./frameworks/cluster/nodes/proxy.zeek
|
||||||
-./frameworks/cluster/nodes/worker.bro
|
-./frameworks/cluster/nodes/worker.zeek
|
||||||
-./frameworks/cluster/setup-connections.bro
|
-./frameworks/cluster/setup-connections.zeek
|
||||||
-./frameworks/intel/cluster.bro
|
-./frameworks/intel/cluster.zeek
|
||||||
-./frameworks/netcontrol/cluster.bro
|
-./frameworks/netcontrol/cluster.zeek
|
||||||
-./frameworks/openflow/cluster.bro
|
-./frameworks/openflow/cluster.zeek
|
||||||
-./frameworks/packet-filter/cluster.bro
|
-./frameworks/packet-filter/cluster.zeek
|
||||||
-./frameworks/sumstats/cluster.bro
|
-./frameworks/sumstats/cluster.zeek
|
||||||
|
|
|
@ -1,11 +1,11 @@
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 245: deprecated (dhcp_discover)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 245: deprecated (dhcp_discover)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 248: deprecated (dhcp_offer)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 248: deprecated (dhcp_offer)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 251: deprecated (dhcp_request)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 251: deprecated (dhcp_request)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 254: deprecated (dhcp_decline)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 254: deprecated (dhcp_decline)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 257: deprecated (dhcp_ack)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 257: deprecated (dhcp_ack)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 260: deprecated (dhcp_nak)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 260: deprecated (dhcp_nak)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 263: deprecated (dhcp_release)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 263: deprecated (dhcp_release)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.bro, line 266: deprecated (dhcp_inform)
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/dhcp/deprecated_events.zeek, line 266: deprecated (dhcp_inform)
|
||||||
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /Users/jon/projects/bro/bro/scripts/broxygen/__load__.bro:10 "Use '@load base/protocols/smb' instead"
|
warning in /Users/jon/projects/bro/bro/scripts/policy/protocols/smb/__load__.zeek, line 1: deprecated script loaded from /Users/jon/projects/bro/bro/scripts/broxygen/__load__.zeek:10 "Use '@load base/protocols/smb' instead"
|
||||||
error in /Users/jon/projects/bro/bro/scripts/policy/frameworks/control/controller.bro, line 22: The '' control command is unknown.
|
error in /Users/jon/projects/bro/bro/scripts/policy/frameworks/control/controller.zeek, line 22: The '' control command is unknown.
|
||||||
<params>, line 1: received termination signal
|
<params>, line 1: received termination signal
|
||||||
|
|
|
@ -1,7 +1,7 @@
|
||||||
:tocdepth: 3
|
:tocdepth: 3
|
||||||
|
|
||||||
broxygen/example.bro
|
broxygen/example.zeek
|
||||||
====================
|
=====================
|
||||||
.. bro:namespace:: BroxygenExample
|
.. bro:namespace:: BroxygenExample
|
||||||
|
|
||||||
This is an example script that demonstrates Broxygen-style
|
This is an example script that demonstrates Broxygen-style
|
||||||
|
@ -27,7 +27,7 @@ And a custom directive does the equivalent references:
|
||||||
.. bro:see:: BroxygenExample::a_var BroxygenExample::ONE SSH::Info
|
.. bro:see:: BroxygenExample::a_var BroxygenExample::ONE SSH::Info
|
||||||
|
|
||||||
:Namespace: BroxygenExample
|
:Namespace: BroxygenExample
|
||||||
:Imports: :doc:`base/frameworks/notice </scripts/base/frameworks/notice/index>`, :doc:`base/protocols/http </scripts/base/protocols/http/index>`, :doc:`policy/frameworks/software/vulnerable.bro </scripts/policy/frameworks/software/vulnerable.bro>`
|
:Imports: :doc:`base/frameworks/notice </scripts/base/frameworks/notice/index>`, :doc:`base/protocols/http </scripts/base/protocols/http/index>`, :doc:`policy/frameworks/software/vulnerable.zeek </scripts/policy/frameworks/software/vulnerable.zeek>`
|
||||||
|
|
||||||
Summary
|
Summary
|
||||||
~~~~~~~
|
~~~~~~~
|
||||||
|
|
|
@ -8,10 +8,10 @@ reference documentation for all Bro scripts (i.e. "Broxygen"). Its only
|
||||||
purpose is to provide an easy way to load all known Bro scripts plus any
|
purpose is to provide an easy way to load all known Bro scripts plus any
|
||||||
extra scripts needed or used by the documentation process.
|
extra scripts needed or used by the documentation process.
|
||||||
|
|
||||||
:doc:`/scripts/broxygen/__load__.bro`
|
:doc:`/scripts/broxygen/__load__.zeek`
|
||||||
|
|
||||||
|
|
||||||
:doc:`/scripts/broxygen/example.bro`
|
:doc:`/scripts/broxygen/example.zeek`
|
||||||
|
|
||||||
This is an example script that demonstrates Broxygen-style
|
This is an example script that demonstrates Broxygen-style
|
||||||
documentation. It generally will make most sense when viewing
|
documentation. It generally will make most sense when viewing
|
||||||
|
|
|
@ -1,5 +1,5 @@
|
||||||
.. toctree::
|
.. toctree::
|
||||||
:maxdepth: 1
|
:maxdepth: 1
|
||||||
|
|
||||||
broxygen/__load__.bro </scripts/broxygen/__load__.bro>
|
broxygen/__load__.zeek </scripts/broxygen/__load__.zeek>
|
||||||
broxygen/example.bro </scripts/broxygen/example.bro>
|
broxygen/example.zeek </scripts/broxygen/example.zeek>
|
||||||
|
|
|
@ -1,4 +1,4 @@
|
||||||
:doc:`/scripts/broxygen/example.bro`
|
:doc:`/scripts/broxygen/example.zeek`
|
||||||
This is an example script that demonstrates Broxygen-style
|
This is an example script that demonstrates Broxygen-style
|
||||||
documentation. It generally will make most sense when viewing
|
documentation. It generally will make most sense when viewing
|
||||||
the script's raw source code and comparing to the HTML-rendered
|
the script's raw source code and comparing to the HTML-rendered
|
||||||
|
|
|
@ -1,4 +1,4 @@
|
||||||
runtime error in /home/jon/pro/zeek/zeek/scripts/base/utils/queue.bro, line 152: vector index assignment failed for invalid type 'myrec', value: [a=T, b=hi, c=<uninitialized>], expression: Queue::ret[Queue::j], call stack:
|
runtime error in /home/jon/pro/zeek/zeek/scripts/base/utils/queue.zeek, line 152: vector index assignment failed for invalid type 'myrec', value: [a=T, b=hi, c=<uninitialized>], expression: Queue::ret[Queue::j], call stack:
|
||||||
#0 Queue::get_vector([initialized=T, vals={[2] = test,[6] = jkl;,[4] = asdf,[1] = goodbye,[5] = 3,[0] = hello,[3] = [a=T, b=hi, c=<uninitialized>]}, settings=[max_len=<uninitialized>], top=7, bottom=0, size=0], [hello, goodbye, test]) at /home/jon/pro/zeek/zeek/testing/btest/.tmp/language.index-assignment-invalid/index-assignment-invalid.bro:19
|
#0 Queue::get_vector([initialized=T, vals={[2] = test,[6] = jkl;,[4] = asdf,[1] = goodbye,[5] = 3,[0] = hello,[3] = [a=T, b=hi, c=<uninitialized>]}, settings=[max_len=<uninitialized>], top=7, bottom=0, size=0], [hello, goodbye, test]) at /home/jon/pro/zeek/zeek/testing/btest/.tmp/language.index-assignment-invalid/index-assignment-invalid.bro:19
|
||||||
#1 bar(55) at /home/jon/pro/zeek/zeek/testing/btest/.tmp/language.index-assignment-invalid/index-assignment-invalid.bro:27
|
#1 bar(55) at /home/jon/pro/zeek/zeek/testing/btest/.tmp/language.index-assignment-invalid/index-assignment-invalid.bro:27
|
||||||
#2 foo(hi, 13) at /home/jon/pro/zeek/zeek/testing/btest/.tmp/language.index-assignment-invalid/index-assignment-invalid.bro:39
|
#2 foo(hi, 13) at /home/jon/pro/zeek/zeek/testing/btest/.tmp/language.index-assignment-invalid/index-assignment-invalid.bro:39
|
||||||
|
|
|
@ -6,6 +6,6 @@
|
||||||
#open 2019-03-24-20-20-10
|
#open 2019-03-24-20-20-10
|
||||||
#fields ts level message location
|
#fields ts level message location
|
||||||
#types time enum string string
|
#types time enum string string
|
||||||
0.000000 Reporter::INFO Tried to remove non-existing item '192.168.1.1' (Intel::ADDR). /home/jgras/devel/zeek/scripts/base/frameworks/intel/./main.bro, lines 563-564
|
0.000000 Reporter::INFO Tried to remove non-existing item '192.168.1.1' (Intel::ADDR). /home/jgras/devel/zeek/scripts/base/frameworks/intel/./main.zeek, lines 563-564
|
||||||
0.000000 Reporter::INFO received termination signal (empty)
|
0.000000 Reporter::INFO received termination signal (empty)
|
||||||
#close 2019-03-24-20-20-10
|
#close 2019-03-24-20-20-10
|
||||||
|
|
|
@ -1 +1 @@
|
||||||
1389719059.311687 warning in /Users/jsiwek/Projects/bro/bro/scripts/base/misc/find-filtered-trace.bro, line 48: The analyzed trace file was determined to contain only TCP control packets, which may indicate it's been pre-filtered. By default, Bro reports the missing segments for this type of trace, but the 'detect_filtered_trace' option may be toggled if that's not desired.
|
1389719059.311687 warning in /Users/jsiwek/Projects/bro/bro/scripts/base/misc/find-filtered-trace.zeek, line 48: The analyzed trace file was determined to contain only TCP control packets, which may indicate it's been pre-filtered. By default, Bro reports the missing segments for this type of trace, but the 'detect_filtered_trace' option may be toggled if that's not desired.
|
||||||
|
|
|
@ -1,4 +1,4 @@
|
||||||
error in /home/robin/bro/master/scripts/base/misc/version.bro, line 54: Version string 1 cannot be parsed
|
error in /home/robin/bro/master/scripts/base/misc/version.zeek, line 54: Version string 1 cannot be parsed
|
||||||
error in /home/robin/bro/master/scripts/base/misc/version.bro, line 54: Version string 12.5 cannot be parsed
|
error in /home/robin/bro/master/scripts/base/misc/version.zeek, line 54: Version string 12.5 cannot be parsed
|
||||||
error in /home/robin/bro/master/scripts/base/misc/version.bro, line 54: Version string 1.12-beta-drunk cannot be parsed
|
error in /home/robin/bro/master/scripts/base/misc/version.zeek, line 54: Version string 1.12-beta-drunk cannot be parsed
|
||||||
error in /home/robin/bro/master/scripts/base/misc/version.bro, line 54: Version string JustARandomString cannot be parsed
|
error in /home/robin/bro/master/scripts/base/misc/version.zeek, line 54: Version string JustARandomString cannot be parsed
|
||||||
|
|
|
@ -4,4 +4,4 @@
|
||||||
# @TEST-EXEC: gunzip -c $TRACES/trunc/mpls-6in6-broken.pcap.gz | bro -C -b -r - %INPUT
|
# @TEST-EXEC: gunzip -c $TRACES/trunc/mpls-6in6-broken.pcap.gz | bro -C -b -r - %INPUT
|
||||||
# @TEST-EXEC: btest-diff weird.log
|
# @TEST-EXEC: btest-diff weird.log
|
||||||
|
|
||||||
@load base/frameworks/notice/weird.bro
|
@load base/frameworks/notice/weird
|
||||||
|
|
|
@ -8,14 +8,14 @@
|
||||||
@prefixes += lcl2
|
@prefixes += lcl2
|
||||||
@TEST-END-FILE
|
@TEST-END-FILE
|
||||||
|
|
||||||
# Since base/utils/site.bro is a script, only a script with the original file
|
# Since base/utils/site.zeek is a script, only a script with the original file
|
||||||
# extension can be loaded here.
|
# extension can be loaded here.
|
||||||
@TEST-START-FILE lcl.base.utils.site.bro
|
@TEST-START-FILE lcl.base.utils.site.zeek
|
||||||
print "loaded lcl.base.utils.site.bro";
|
print "loaded lcl.base.utils.site.zeek";
|
||||||
@TEST-END-FILE
|
@TEST-END-FILE
|
||||||
|
|
||||||
@TEST-START-FILE lcl2.base.utils.site.bro
|
@TEST-START-FILE lcl2.base.utils.site.zeek
|
||||||
print "loaded lcl2.base.utils.site.bro";
|
print "loaded lcl2.base.utils.site.zeek";
|
||||||
@TEST-END-FILE
|
@TEST-END-FILE
|
||||||
|
|
||||||
# For a script package like base/protocols/http/, either of the recognized
|
# For a script package like base/protocols/http/, either of the recognized
|
||||||
|
|
|
@ -1,6 +1,6 @@
|
||||||
# This test is meant to cover whether the set of scripts that get loaded by
|
# This test is meant to cover whether the set of scripts that get loaded by
|
||||||
# default in bare mode matches a baseline of known defaults. The baseline
|
# default in bare mode matches a baseline of known defaults. The baseline
|
||||||
# should only need updating if something new is @load'd from init-bare.bro
|
# should only need updating if something new is @load'd from init-bare.zeek
|
||||||
# (or from an @load'd descendent of it).
|
# (or from an @load'd descendent of it).
|
||||||
#
|
#
|
||||||
# As the output has absolute paths in it, we need to remove the common
|
# As the output has absolute paths in it, we need to remove the common
|
||||||
|
|
|
@ -5,5 +5,5 @@
|
||||||
# when writing a new bro scripts.
|
# when writing a new bro scripts.
|
||||||
#
|
#
|
||||||
# @TEST-EXEC: test -d $DIST/scripts
|
# @TEST-EXEC: test -d $DIST/scripts
|
||||||
# @TEST-EXEC: for script in `find $DIST/scripts/ -name \*\.bro`; do bro -b --parse-only $script >>errors 2>&1; done
|
# @TEST-EXEC: for script in `find $DIST/scripts/ -name \*\.zeek`; do bro -b --parse-only $script >>errors 2>&1; done
|
||||||
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-abspath | $SCRIPTS/diff-sort" btest-diff errors
|
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-abspath | $SCRIPTS/diff-sort" btest-diff errors
|
||||||
|
|
|
@ -28,7 +28,7 @@ def find_scripts():
|
||||||
|
|
||||||
for r, d, f in os.walk(scriptdir):
|
for r, d, f in os.walk(scriptdir):
|
||||||
for fname in f:
|
for fname in f:
|
||||||
if fname.endswith(".bro"):
|
if fname.endswith(".zeek") or fname.endswith(".bro"):
|
||||||
scripts.append(os.path.join(r, fname))
|
scripts.append(os.path.join(r, fname))
|
||||||
|
|
||||||
return scripts
|
return scripts
|
||||||
|
|
|
@ -1,19 +1,19 @@
|
||||||
# Makes sure that all base/* scripts are loaded by default via init-default.bro;
|
# Makes sure that all base/* scripts are loaded by default via
|
||||||
# and that all scripts loaded there in there actually exist.
|
# init-default.zeek; and that all scripts loaded there actually exist.
|
||||||
#
|
#
|
||||||
# This test will fail if a new bro script is added under the scripts/base/
|
# This test will fail if a new bro script is added under the scripts/base/
|
||||||
# directory and it is not also added as an @load in base/init-default.bro.
|
# directory and it is not also added as an @load in base/init-default.zeek.
|
||||||
# In some cases, a script in base is loaded based on the bro configuration
|
# In some cases, a script in base is loaded based on the bro configuration
|
||||||
# (e.g. cluster operation), and in such cases, the missing_loads baseline
|
# (e.g. cluster operation), and in such cases, the missing_loads baseline
|
||||||
# can be adjusted to tolerate that.
|
# can be adjusted to tolerate that.
|
||||||
|
|
||||||
#@TEST-EXEC: test -d $DIST/scripts/base
|
#@TEST-EXEC: test -d $DIST/scripts/base
|
||||||
#@TEST-EXEC: test -e $DIST/scripts/base/init-default.bro
|
#@TEST-EXEC: test -e $DIST/scripts/base/init-default.zeek
|
||||||
#@TEST-EXEC: ( cd $DIST/scripts/base && find . -name '*.bro' ) | sort >"all scripts found"
|
#@TEST-EXEC: ( cd $DIST/scripts/base && find . -name '*.zeek' ) | sort >"all scripts found"
|
||||||
#@TEST-EXEC: bro misc/loaded-scripts
|
#@TEST-EXEC: bro misc/loaded-scripts
|
||||||
#@TEST-EXEC: (test -L $BUILD && basename $(readlink $BUILD) || basename $BUILD) >buildprefix
|
#@TEST-EXEC: (test -L $BUILD && basename $(readlink $BUILD) || basename $BUILD) >buildprefix
|
||||||
#@TEST-EXEC: cat loaded_scripts.log | egrep -v "/build/scripts/|$(cat buildprefix)/scripts/|/loaded-scripts.bro|#" | sed 's#/./#/#g' >loaded_scripts.log.tmp
|
#@TEST-EXEC: cat loaded_scripts.log | egrep -v "/build/scripts/|$(cat buildprefix)/scripts/|/loaded-scripts.zeek|#" | sed 's#/./#/#g' >loaded_scripts.log.tmp
|
||||||
#@TEST-EXEC: cat loaded_scripts.log.tmp | sed 's/ //g' | sed -e ':a' -e '$!N' -e 's/^\(.*\).*\n\1.*/\1/' -e 'ta' >prefix
|
#@TEST-EXEC: cat loaded_scripts.log.tmp | sed 's/ //g' | sed -e ':a' -e '$!N' -e 's/^\(.*\).*\n\1.*/\1/' -e 'ta' >prefix
|
||||||
#@TEST-EXEC: cat loaded_scripts.log.tmp | sed 's/ //g' | sed "s#`cat prefix`#./#g" | sort >init-default.bro
|
#@TEST-EXEC: cat loaded_scripts.log.tmp | sed 's/ //g' | sed "s#`cat prefix`#./#g" | sort >init-default.zeek
|
||||||
#@TEST-EXEC: diff -u "all scripts found" init-default.bro | egrep "^-[^-]" > missing_loads
|
#@TEST-EXEC: diff -u "all scripts found" init-default.zeek | egrep "^-[^-]" > missing_loads
|
||||||
#@TEST-EXEC: btest-diff missing_loads
|
#@TEST-EXEC: btest-diff missing_loads
|
||||||
|
|
|
@ -1,12 +1,12 @@
|
||||||
# Makes sure that all policy/* scripts are loaded in
|
# Makes sure that all policy/* scripts are loaded in
|
||||||
# scripts/test-all-policy.bro and that all scripts loaded there actually exist.
|
# scripts/test-all-policy.zeek and that all scripts loaded there actually exist.
|
||||||
#
|
#
|
||||||
# This test will fail if new bro scripts are added to the scripts/policy/
|
# This test will fail if new bro scripts are added to the scripts/policy/
|
||||||
# directory. Correcting that just involves updating scripts/test-all-policy.bro
|
# directory. Correcting that just involves updating
|
||||||
# to @load the new bro scripts.
|
# scripts/test-all-policy.zeek to @load the new bro scripts.
|
||||||
|
|
||||||
@TEST-EXEC: test -e $DIST/scripts/test-all-policy.bro
|
@TEST-EXEC: test -e $DIST/scripts/test-all-policy.zeek
|
||||||
@TEST-EXEC: test -d $DIST/scripts
|
@TEST-EXEC: test -d $DIST/scripts
|
||||||
@TEST-EXEC: ( cd $DIST/scripts/policy && find . -name '*.bro' ) | sort >"all scripts found"
|
@TEST-EXEC: ( cd $DIST/scripts/policy && find . -name '*.zeek' ) | sort >"all scripts found"
|
||||||
@TEST-EXEC: cat $DIST/scripts/test-all-policy.bro | grep '@load' | sed 'sm^\( *# *\)\{0,\}@load *m./mg' | sort >test-all-policy.bro
|
@TEST-EXEC: cat $DIST/scripts/test-all-policy.zeek | grep '@load' | sed 'sm^\( *# *\)\{0,\}@load *m./mg' | sort >test-all-policy.zeek
|
||||||
@TEST-EXEC: diff -u "all scripts found" test-all-policy.bro 1>&2
|
@TEST-EXEC: diff -u "all scripts found" test-all-policy.zeek 1>&2
|
||||||
|
|
|
@ -2,7 +2,7 @@
|
||||||
# @TEST-EXEC: btest-diff example.rst
|
# @TEST-EXEC: btest-diff example.rst
|
||||||
|
|
||||||
@TEST-START-FILE broxygen.config
|
@TEST-START-FILE broxygen.config
|
||||||
script broxygen/example.bro example.rst
|
script broxygen/example.zeek example.rst
|
||||||
@TEST-END-FILE
|
@TEST-END-FILE
|
||||||
|
|
||||||
@load broxygen/example.bro
|
@load broxygen/example
|
||||||
|
|
|
@ -3,7 +3,7 @@
|
||||||
# @TEST-EXEC: btest-diff test.rst
|
# @TEST-EXEC: btest-diff test.rst
|
||||||
|
|
||||||
@TEST-START-FILE broxygen.config
|
@TEST-START-FILE broxygen.config
|
||||||
script_summary broxygen/example.bro test.rst
|
script_summary broxygen/example.zeek test.rst
|
||||||
@TEST-END-FILE
|
@TEST-END-FILE
|
||||||
|
|
||||||
@load broxygen
|
@load broxygen
|
||||||
|
|
|
@ -2,7 +2,7 @@
|
||||||
# @TEST-EXEC: bro -b %INPUT
|
# @TEST-EXEC: bro -b %INPUT
|
||||||
# @TEST-EXEC: btest-diff testing.log
|
# @TEST-EXEC: btest-diff testing.log
|
||||||
|
|
||||||
@load tuning/json-logs.bro
|
@load tuning/json-logs
|
||||||
|
|
||||||
module testing;
|
module testing;
|
||||||
|
|
||||||
|
|
|
@ -5,5 +5,5 @@
|
||||||
# @TEST-EXEC: btest-diff known_modbus.log
|
# @TEST-EXEC: btest-diff known_modbus.log
|
||||||
#
|
#
|
||||||
|
|
||||||
@load protocols/modbus/known-masters-slaves.bro
|
@load protocols/modbus/known-masters-slaves
|
||||||
@load protocols/modbus/track-memmap.bro
|
@load protocols/modbus/track-memmap
|
||||||
|
|
|
@ -3,4 +3,4 @@
|
||||||
# @TEST-EXEC: bro -r $TRACES/tls/CVE-2015-3194.pcap %INPUT
|
# @TEST-EXEC: bro -r $TRACES/tls/CVE-2015-3194.pcap %INPUT
|
||||||
# @TEST-EXEC: btest-diff ssl.log
|
# @TEST-EXEC: btest-diff ssl.log
|
||||||
|
|
||||||
@load protocols/ssl/validate-certs.bro
|
@load protocols/ssl/validate-certs
|
||||||
|
|
|
@ -16,7 +16,7 @@
|
||||||
|
|
||||||
@load base/protocols/ssl
|
@load base/protocols/ssl
|
||||||
@load base/files/x509
|
@load base/files/x509
|
||||||
@load protocols/ssl/extract-certs-pem.bro
|
@load protocols/ssl/extract-certs-pem
|
||||||
|
|
||||||
module SSL;
|
module SSL;
|
||||||
|
|
||||||
|
|
|
@ -1,6 +1,6 @@
|
||||||
# @TEST-EXEC: bro -r $TRACES/smtp.trace policy/misc/dump-events.bro %INPUT >all-events.log
|
# @TEST-EXEC: bro -r $TRACES/smtp.trace policy/misc/dump-events %INPUT >all-events.log
|
||||||
# @TEST-EXEC: bro -r $TRACES/smtp.trace policy/misc/dump-events.bro %INPUT DumpEvents::include_args=F >all-events-no-args.log
|
# @TEST-EXEC: bro -r $TRACES/smtp.trace policy/misc/dump-events %INPUT DumpEvents::include_args=F >all-events-no-args.log
|
||||||
# @TEST-EXEC: bro -r $TRACES/smtp.trace policy/misc/dump-events.bro %INPUT DumpEvents::include=/smtp_/ >smtp-events.log
|
# @TEST-EXEC: bro -r $TRACES/smtp.trace policy/misc/dump-events %INPUT DumpEvents::include=/smtp_/ >smtp-events.log
|
||||||
#
|
#
|
||||||
# @TEST-EXEC: btest-diff all-events.log
|
# @TEST-EXEC: btest-diff all-events.log
|
||||||
# @TEST-EXEC: btest-diff all-events-no-args.log
|
# @TEST-EXEC: btest-diff all-events-no-args.log
|
||||||
|
|
|
@ -2,7 +2,7 @@
|
||||||
# @TEST-EXEC: btest-bg-wait 20
|
# @TEST-EXEC: btest-bg-wait 20
|
||||||
# @TEST-EXEC: btest-diff bro/weird_stats.log
|
# @TEST-EXEC: btest-diff bro/weird_stats.log
|
||||||
|
|
||||||
@load misc/weird-stats.bro
|
@load misc/weird-stats
|
||||||
|
|
||||||
redef exit_only_after_terminate = T;
|
redef exit_only_after_terminate = T;
|
||||||
redef WeirdStats::weird_stat_interval = 5sec;
|
redef WeirdStats::weird_stat_interval = 5sec;
|
||||||
|
|
|
@ -1,6 +1,6 @@
|
||||||
# @TEST-EXEC: bro -C -r $TRACES/tls/missing-intermediate.pcap $SCRIPTS/external-ca-list.bro %INPUT
|
# @TEST-EXEC: bro -C -r $TRACES/tls/missing-intermediate.pcap $SCRIPTS/external-ca-list.bro %INPUT
|
||||||
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-x509-names | $SCRIPTS/diff-remove-timestamps" btest-diff ssl.log
|
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-x509-names | $SCRIPTS/diff-remove-timestamps" btest-diff ssl.log
|
||||||
|
|
||||||
@load protocols/ssl/validate-certs.bro
|
@load protocols/ssl/validate-certs
|
||||||
|
|
||||||
redef SSL::ssl_cache_intermediate_ca = F;
|
redef SSL::ssl_cache_intermediate_ca = F;
|
||||||
|
|
|
@ -4,4 +4,4 @@
|
||||||
# @TEST-EXEC: cat ssl.log >> ssl-all.log
|
# @TEST-EXEC: cat ssl.log >> ssl-all.log
|
||||||
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-x509-names | $SCRIPTS/diff-remove-timestamps" btest-diff ssl-all.log
|
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-x509-names | $SCRIPTS/diff-remove-timestamps" btest-diff ssl-all.log
|
||||||
|
|
||||||
@load protocols/ssl/validate-certs.bro
|
@load protocols/ssl/validate-certs
|
||||||
|
|
|
@ -5,7 +5,7 @@
|
||||||
# @TEST-EXEC: btest-diff .stdout
|
# @TEST-EXEC: btest-diff .stdout
|
||||||
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-x509-names | $SCRIPTS/diff-remove-timestamps" btest-diff ssl-all.log
|
# @TEST-EXEC: TEST_DIFF_CANONIFIER="$SCRIPTS/diff-remove-x509-names | $SCRIPTS/diff-remove-timestamps" btest-diff ssl-all.log
|
||||||
|
|
||||||
@load protocols/ssl/validate-sct.bro
|
@load protocols/ssl/validate-sct
|
||||||
|
|
||||||
module SSL;
|
module SSL;
|
||||||
|
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue