Add note to Traces/README about possible malware in pe/pe.trace

This commit is contained in:
Tim Wojtulewicz 2025-01-30 13:28:35 -07:00
parent 430e3ab940
commit a5b0a9467d

View file

@ -39,3 +39,7 @@ Trace Index/Sources:
- http/docker-http-upgrade.pcap
Provided by blightzero on #4068
https://github.com/zeek/zeek/issues/4068
- pe/pe.trace
VirusTotal reports that this file contains malware. The PE analyzer was originally added
to decode info for malware, so this is expected. See
https://zeekorg.slack.com/archives/CSZBXF6TH/p1738261449655049