diff --git a/scripts/policy/frameworks/intel/removal.bro b/scripts/policy/frameworks/intel/removal.bro new file mode 100644 index 0000000000..cc4bb42921 --- /dev/null +++ b/scripts/policy/frameworks/intel/removal.bro @@ -0,0 +1,23 @@ +##! This script enables removal of intelligence items. + +@load base/frameworks/intel + +module Intel; + +export { + redef record Intel::MetaData += { + ## A boolean value to indicate whether the item should be removed. + remove: bool &default=F; + }; +} + +hook Intel::filter_item(item: Item) + { + if ( item$meta$remove ) + { + Intel::remove(item); + # Prevent readding + break; + } + } +