mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
Merge remote-tracking branch 'origin/topic/bbannier/cmake-format-zeek-add-analyzer'
* origin/topic/bbannier/cmake-format-zeek-add-analyzer: Always break lines when formatting `spicy_add_analyzer` Fix formatting of `zeek_add_plugin`
This commit is contained in:
commit
daaf3142bf
100 changed files with 462 additions and 829 deletions
|
@ -72,10 +72,23 @@
|
||||||
"SOURCES": "*",
|
"SOURCES": "*",
|
||||||
"MODULES": "*"
|
"MODULES": "*"
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
"zeek_add_plugin": {
|
||||||
|
"kwargs": {
|
||||||
|
"INCLUDE_DIRS": "*",
|
||||||
|
"DEPENDENCIES": "*",
|
||||||
|
"SOURCES": "*",
|
||||||
|
"BIFS": "*",
|
||||||
|
"PAC": "*"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"format": {
|
"format": {
|
||||||
|
"always_wrap": [
|
||||||
|
"spicy_add_analyzer",
|
||||||
|
"zeek_add_plugin"
|
||||||
|
],
|
||||||
"line_width": 100,
|
"line_width": 100,
|
||||||
"tab_size": 4,
|
"tab_size": 4,
|
||||||
"separate_ctrl_name_with_space": true,
|
"separate_ctrl_name_with_space": true,
|
||||||
|
|
|
@ -1,13 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek BitTorrent
|
||||||
BitTorrent
|
SOURCES BitTorrent.cc BitTorrentTracker.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
BitTorrent.cc
|
PAC bittorrent.pac bittorrent-analyzer.pac bittorrent-protocol.pac)
|
||||||
BitTorrentTracker.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
bittorrent.pac
|
|
||||||
bittorrent-analyzer.pac
|
|
||||||
bittorrent-protocol.pac)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek ConnSize
|
||||||
ConnSize
|
SOURCES ConnSize.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
ConnSize.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,17 +1,6 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek DCE_RPC
|
||||||
DCE_RPC
|
SOURCES DCE_RPC.cc Plugin.cc
|
||||||
SOURCES
|
BIFS consts.bif types.bif events.bif
|
||||||
DCE_RPC.cc
|
PAC dce_rpc.pac dce_rpc-protocol.pac dce_rpc-analyzer.pac dce_rpc-auth.pac endpoint-atsvc.pac
|
||||||
Plugin.cc
|
endpoint-epmapper.pac)
|
||||||
BIFS
|
|
||||||
consts.bif
|
|
||||||
types.bif
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
dce_rpc.pac
|
|
||||||
dce_rpc-protocol.pac
|
|
||||||
dce_rpc-analyzer.pac
|
|
||||||
dce_rpc-auth.pac
|
|
||||||
endpoint-atsvc.pac
|
|
||||||
endpoint-epmapper.pac)
|
|
||||||
|
|
|
@ -1,14 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek DHCP
|
||||||
DHCP
|
SOURCES DHCP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif types.bif
|
||||||
DHCP.cc
|
PAC dhcp.pac dhcp-protocol.pac dhcp-analyzer.pac dhcp-options.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
types.bif
|
|
||||||
PAC
|
|
||||||
dhcp.pac
|
|
||||||
dhcp-protocol.pac
|
|
||||||
dhcp-analyzer.pac
|
|
||||||
dhcp-options.pac)
|
|
||||||
|
|
|
@ -1,13 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek DNP3
|
||||||
DNP3
|
SOURCES DNP3.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
DNP3.cc
|
PAC dnp3.pac dnp3-analyzer.pac dnp3-protocol.pac dnp3-objects.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
dnp3.pac
|
|
||||||
dnp3-analyzer.pac
|
|
||||||
dnp3-protocol.pac
|
|
||||||
dnp3-objects.pac)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek DNS
|
||||||
DNS
|
SOURCES DNS.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
DNS.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek File
|
||||||
File
|
SOURCES File.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
File.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
spicy_add_analyzer(NAME Finger SOURCES finger.spicy finger.evt LEGACY legacy)
|
spicy_add_analyzer(
|
||||||
|
NAME Finger
|
||||||
|
SOURCES finger.spicy finger.evt LEGACY legacy)
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Finger
|
||||||
Finger
|
SOURCES Finger.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
Finger.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek FTP
|
||||||
FTP
|
SOURCES FTP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
FTP.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Gnutella
|
||||||
Gnutella
|
SOURCES Gnutella.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
Gnutella.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,13 +1,6 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek GSSAPI
|
||||||
GSSAPI
|
SOURCES GSSAPI.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
GSSAPI.cc
|
PAC gssapi.pac gssapi-protocol.pac gssapi-analyzer.pac
|
||||||
Plugin.cc
|
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac)
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
gssapi.pac
|
|
||||||
gssapi-protocol.pac
|
|
||||||
gssapi-analyzer.pac
|
|
||||||
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek HTTP
|
||||||
HTTP
|
SOURCES HTTP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
HTTP.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Ident
|
||||||
Ident
|
SOURCES Ident.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
Ident.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek IMAP
|
||||||
IMAP
|
SOURCES Plugin.cc IMAP.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
Plugin.cc
|
PAC imap.pac imap-analyzer.pac imap-protocol.pac)
|
||||||
IMAP.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
imap.pac
|
|
||||||
imap-analyzer.pac
|
|
||||||
imap-protocol.pac)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek IRC
|
||||||
IRC
|
SOURCES IRC.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
IRC.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,28 +1,20 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek KRB
|
||||||
KRB
|
SOURCES Plugin.cc KRB.cc KRB_TCP.cc
|
||||||
SOURCES
|
BIFS types.bif events.bif
|
||||||
Plugin.cc
|
PAC krb.pac
|
||||||
KRB.cc
|
krb-protocol.pac
|
||||||
KRB_TCP.cc
|
krb-analyzer.pac
|
||||||
BIFS
|
krb-asn1.pac
|
||||||
types.bif
|
krb-defs.pac
|
||||||
events.bif
|
krb-types.pac
|
||||||
PAC
|
krb-padata.pac
|
||||||
krb.pac
|
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac
|
||||||
krb-protocol.pac
|
PAC krb_TCP.pac
|
||||||
krb-analyzer.pac
|
krb-protocol.pac
|
||||||
krb-asn1.pac
|
krb-analyzer.pac
|
||||||
krb-defs.pac
|
krb-asn1.pac
|
||||||
krb-types.pac
|
krb-defs.pac
|
||||||
krb-padata.pac
|
krb-types.pac
|
||||||
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac
|
krb-padata.pac
|
||||||
PAC
|
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac)
|
||||||
krb_TCP.pac
|
|
||||||
krb-protocol.pac
|
|
||||||
krb-analyzer.pac
|
|
||||||
krb-asn1.pac
|
|
||||||
krb-defs.pac
|
|
||||||
krb-types.pac
|
|
||||||
krb-padata.pac
|
|
||||||
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac)
|
|
||||||
|
|
|
@ -1,13 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Login
|
||||||
Login
|
SOURCES Login.cc RSH.cc Telnet.cc Rlogin.cc NVT.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
Login.cc
|
|
||||||
RSH.cc
|
|
||||||
Telnet.cc
|
|
||||||
Rlogin.cc
|
|
||||||
NVT.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -4,11 +4,6 @@
|
||||||
# this code was written.
|
# this code was written.
|
||||||
|
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek MIME
|
||||||
MIME
|
SOURCES MIME.cc Plugin.cc
|
||||||
SOURCES
|
BIFS consts.bif events.bif)
|
||||||
MIME.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
consts.bif
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Modbus
|
||||||
Modbus
|
SOURCES Modbus.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
Modbus.cc
|
PAC modbus.pac modbus-analyzer.pac modbus-protocol.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
modbus.pac
|
|
||||||
modbus-analyzer.pac
|
|
||||||
modbus-protocol.pac)
|
|
||||||
|
|
|
@ -1,26 +1,20 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek MQTT
|
||||||
MQTT
|
SOURCES MQTT.cc Plugin.cc
|
||||||
SOURCES
|
BIFS types.bif events.bif
|
||||||
MQTT.cc
|
PAC mqtt.pac
|
||||||
Plugin.cc
|
mqtt-protocol.pac
|
||||||
BIFS
|
commands/connect.pac
|
||||||
types.bif
|
commands/connack.pac
|
||||||
events.bif
|
commands/publish.pac
|
||||||
PAC
|
commands/puback.pac
|
||||||
mqtt.pac
|
commands/pubrec.pac
|
||||||
mqtt-protocol.pac
|
commands/pubrel.pac
|
||||||
commands/connect.pac
|
commands/pubcomp.pac
|
||||||
commands/connack.pac
|
commands/subscribe.pac
|
||||||
commands/publish.pac
|
commands/suback.pac
|
||||||
commands/puback.pac
|
commands/unsuback.pac
|
||||||
commands/pubrec.pac
|
commands/unsubscribe.pac
|
||||||
commands/pubrel.pac
|
commands/disconnect.pac
|
||||||
commands/pubcomp.pac
|
commands/pingreq.pac
|
||||||
commands/subscribe.pac
|
commands/pingresp.pac)
|
||||||
commands/suback.pac
|
|
||||||
commands/unsuback.pac
|
|
||||||
commands/unsubscribe.pac
|
|
||||||
commands/disconnect.pac
|
|
||||||
commands/pingreq.pac
|
|
||||||
commands/pingresp.pac)
|
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek MySQL
|
||||||
MySQL
|
SOURCES MySQL.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
MySQL.cc
|
PAC mysql.pac mysql-analyzer.pac mysql-protocol.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
mysql.pac
|
|
||||||
mysql-analyzer.pac
|
|
||||||
mysql-protocol.pac)
|
|
||||||
|
|
|
@ -1,11 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek NCP
|
||||||
NCP
|
SOURCES NCP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif consts.bif
|
||||||
NCP.cc
|
PAC ncp.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
consts.bif
|
|
||||||
PAC
|
|
||||||
ncp.pac)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek NetBIOS
|
||||||
NetBIOS
|
SOURCES NetbiosSSN.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
NetbiosSSN.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,13 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek NTLM
|
||||||
NTLM
|
SOURCES NTLM.cc Plugin.cc
|
||||||
SOURCES
|
BIFS types.bif events.bif
|
||||||
NTLM.cc
|
PAC ntlm.pac ntlm-protocol.pac ntlm-analyzer.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
types.bif
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
ntlm.pac
|
|
||||||
ntlm-protocol.pac
|
|
||||||
ntlm-analyzer.pac)
|
|
||||||
|
|
|
@ -1,14 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek NTP
|
||||||
NTP
|
SOURCES NTP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS types.bif events.bif
|
||||||
NTP.cc
|
PAC ntp.pac ntp-analyzer.pac ntp-mode7.pac ntp-protocol.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
types.bif
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
ntp.pac
|
|
||||||
ntp-analyzer.pac
|
|
||||||
ntp-mode7.pac
|
|
||||||
ntp-protocol.pac)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(Zeek PIA SOURCES PIA.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
Zeek PIA
|
||||||
|
SOURCES PIA.cc Plugin.cc)
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek POP3
|
||||||
POP3
|
SOURCES POP3.cc Plugin.cc
|
||||||
SOURCES
|
BIFS consts.bif events.bif)
|
||||||
POP3.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
consts.bif
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek RADIUS
|
||||||
RADIUS
|
SOURCES RADIUS.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
RADIUS.cc
|
PAC radius.pac radius-analyzer.pac radius-protocol.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
radius.pac
|
|
||||||
radius-analyzer.pac
|
|
||||||
radius-protocol.pac)
|
|
||||||
|
|
|
@ -1,19 +1,7 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek RDP
|
||||||
RDP
|
SOURCES RDPEUDP.cc RDP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif types.bif
|
||||||
RDPEUDP.cc
|
PAC rdp.pac rdp-analyzer.pac rdp-protocol.pac
|
||||||
RDP.cc
|
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac
|
||||||
Plugin.cc
|
PAC rdpeudp.pac rdpeudp-analyzer.pac rdpeudp-protocol.pac)
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
types.bif
|
|
||||||
PAC
|
|
||||||
rdp.pac
|
|
||||||
rdp-analyzer.pac
|
|
||||||
rdp-protocol.pac
|
|
||||||
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac
|
|
||||||
PAC
|
|
||||||
rdpeudp.pac
|
|
||||||
rdpeudp-analyzer.pac
|
|
||||||
rdpeudp-protocol.pac)
|
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek RFB
|
||||||
RFB
|
SOURCES RFB.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
RFB.cc
|
PAC rfb.pac rfb-analyzer.pac rfb-protocol.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
rfb.pac
|
|
||||||
rfb-analyzer.pac
|
|
||||||
rfb-protocol.pac)
|
|
||||||
|
|
|
@ -1,12 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek RPC
|
||||||
RPC
|
SOURCES RPC.cc NFS.cc MOUNT.cc Portmap.cc XDR.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
RPC.cc
|
|
||||||
NFS.cc
|
|
||||||
MOUNT.cc
|
|
||||||
Portmap.cc
|
|
||||||
XDR.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,17 +1,6 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SIP
|
||||||
SIP
|
SOURCES Plugin.cc SIP.cc SIP_TCP.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
Plugin.cc
|
PAC sip.pac sip-analyzer.pac sip-protocol.pac
|
||||||
SIP.cc
|
PAC sip_TCP.pac sip-protocol.pac sip-analyzer.pac)
|
||||||
SIP_TCP.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
sip.pac
|
|
||||||
sip-analyzer.pac
|
|
||||||
sip-protocol.pac
|
|
||||||
PAC
|
|
||||||
sip_TCP.pac
|
|
||||||
sip-protocol.pac
|
|
||||||
sip-analyzer.pac)
|
|
||||||
|
|
|
@ -1,88 +1,83 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SMB
|
||||||
SMB
|
SOURCES SMB.cc Plugin.cc
|
||||||
SOURCES
|
BIFS # SMB 1.
|
||||||
SMB.cc
|
smb1_com_check_directory.bif
|
||||||
Plugin.cc
|
smb1_com_close.bif
|
||||||
BIFS
|
smb1_com_create_directory.bif
|
||||||
# SMB 1.
|
smb1_com_echo.bif
|
||||||
smb1_com_check_directory.bif
|
smb1_com_logoff_andx.bif
|
||||||
smb1_com_close.bif
|
smb1_com_negotiate.bif
|
||||||
smb1_com_create_directory.bif
|
smb1_com_nt_create_andx.bif
|
||||||
smb1_com_echo.bif
|
smb1_com_nt_cancel.bif
|
||||||
smb1_com_logoff_andx.bif
|
smb1_com_query_information.bif
|
||||||
smb1_com_negotiate.bif
|
smb1_com_read_andx.bif
|
||||||
smb1_com_nt_create_andx.bif
|
smb1_com_session_setup_andx.bif
|
||||||
smb1_com_nt_cancel.bif
|
smb1_com_transaction.bif
|
||||||
smb1_com_query_information.bif
|
smb1_com_transaction_secondary.bif
|
||||||
smb1_com_read_andx.bif
|
smb1_com_transaction2.bif
|
||||||
smb1_com_session_setup_andx.bif
|
smb1_com_transaction2_secondary.bif
|
||||||
smb1_com_transaction.bif
|
smb1_com_tree_connect_andx.bif
|
||||||
smb1_com_transaction_secondary.bif
|
smb1_com_tree_disconnect.bif
|
||||||
smb1_com_transaction2.bif
|
smb1_com_write_andx.bif
|
||||||
smb1_com_transaction2_secondary.bif
|
smb1_events.bif
|
||||||
smb1_com_tree_connect_andx.bif
|
# SMB 2.
|
||||||
smb1_com_tree_disconnect.bif
|
smb2_com_close.bif
|
||||||
smb1_com_write_andx.bif
|
smb2_com_create.bif
|
||||||
smb1_events.bif
|
smb2_com_negotiate.bif
|
||||||
# SMB 2.
|
smb2_com_read.bif
|
||||||
smb2_com_close.bif
|
smb2_com_session_setup.bif
|
||||||
smb2_com_create.bif
|
smb2_com_set_info.bif
|
||||||
smb2_com_negotiate.bif
|
smb2_com_tree_connect.bif
|
||||||
smb2_com_read.bif
|
smb2_com_tree_disconnect.bif
|
||||||
smb2_com_session_setup.bif
|
smb2_com_write.bif
|
||||||
smb2_com_set_info.bif
|
smb2_com_transform_header.bif
|
||||||
smb2_com_tree_connect.bif
|
smb2_events.bif
|
||||||
smb2_com_tree_disconnect.bif
|
# Common boilerplate.
|
||||||
smb2_com_write.bif
|
events.bif
|
||||||
smb2_com_transform_header.bif
|
consts.bif
|
||||||
smb2_events.bif
|
types.bif
|
||||||
# Common boilerplate.
|
PAC # Common boilerplate.
|
||||||
events.bif
|
smb.pac
|
||||||
consts.bif
|
smb-common.pac
|
||||||
types.bif
|
smb-strings.pac
|
||||||
PAC
|
smb-time.pac
|
||||||
# Common boilerplate.
|
smb-pipe.pac
|
||||||
smb.pac
|
smb-gssapi.pac
|
||||||
smb-common.pac
|
smb-mailslot.pac
|
||||||
smb-strings.pac
|
# SMB 1.
|
||||||
smb-time.pac
|
smb1-protocol.pac
|
||||||
smb-pipe.pac
|
smb1-com-check-directory.pac
|
||||||
smb-gssapi.pac
|
smb1-com-close.pac
|
||||||
smb-mailslot.pac
|
smb1-com-create-directory.pac
|
||||||
# SMB 1.
|
smb1-com-echo.pac
|
||||||
smb1-protocol.pac
|
smb1-com-locking-andx.pac
|
||||||
smb1-com-check-directory.pac
|
smb1-com-logoff-andx.pac
|
||||||
smb1-com-close.pac
|
smb1-com-negotiate.pac
|
||||||
smb1-com-create-directory.pac
|
smb1-com-nt-cancel.pac
|
||||||
smb1-com-echo.pac
|
smb1-com-nt-create-andx.pac
|
||||||
smb1-com-locking-andx.pac
|
smb1-com-nt-transact.pac
|
||||||
smb1-com-logoff-andx.pac
|
smb1-com-query-information.pac
|
||||||
smb1-com-negotiate.pac
|
smb1-com-read-andx.pac
|
||||||
smb1-com-nt-cancel.pac
|
smb1-com-session-setup-andx.pac
|
||||||
smb1-com-nt-create-andx.pac
|
smb1-com-transaction-secondary.pac
|
||||||
smb1-com-nt-transact.pac
|
smb1-com-transaction.pac
|
||||||
smb1-com-query-information.pac
|
smb1-com-transaction2.pac
|
||||||
smb1-com-read-andx.pac
|
smb1-com-transaction2-secondary.pac
|
||||||
smb1-com-session-setup-andx.pac
|
smb1-com-tree-connect-andx.pac
|
||||||
smb1-com-transaction-secondary.pac
|
smb1-com-tree-disconnect.pac
|
||||||
smb1-com-transaction.pac
|
smb1-com-write-andx.pac
|
||||||
smb1-com-transaction2.pac
|
# SMB 2.
|
||||||
smb1-com-transaction2-secondary.pac
|
smb2-protocol.pac
|
||||||
smb1-com-tree-connect-andx.pac
|
smb2-com-close.pac
|
||||||
smb1-com-tree-disconnect.pac
|
smb2-com-create.pac
|
||||||
smb1-com-write-andx.pac
|
smb2-com-ioctl.pac
|
||||||
# SMB 2.
|
smb2-com-lock.pac
|
||||||
smb2-protocol.pac
|
smb2-com-negotiate.pac
|
||||||
smb2-com-close.pac
|
smb2-com-read.pac
|
||||||
smb2-com-create.pac
|
smb2-com-session-setup.pac
|
||||||
smb2-com-ioctl.pac
|
smb2-com-set-info.pac
|
||||||
smb2-com-lock.pac
|
smb2-com-tree-connect.pac
|
||||||
smb2-com-negotiate.pac
|
smb2-com-tree-disconnect.pac
|
||||||
smb2-com-read.pac
|
smb2-com-write.pac
|
||||||
smb2-com-session-setup.pac
|
smb2-com-transform-header.pac)
|
||||||
smb2-com-set-info.pac
|
|
||||||
smb2-com-tree-connect.pac
|
|
||||||
smb2-com-tree-disconnect.pac
|
|
||||||
smb2-com-write.pac
|
|
||||||
smb2-com-transform-header.pac)
|
|
||||||
|
|
|
@ -1,11 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SMTP
|
||||||
SMTP
|
SOURCES SMTP.cc BDAT.cc Plugin.cc
|
||||||
SOURCES
|
BIFS consts.bif events.bif functions.bif)
|
||||||
SMTP.cc
|
|
||||||
BDAT.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
consts.bif
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,14 +1,6 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SNMP
|
||||||
SNMP
|
SOURCES SNMP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS types.bif events.bif
|
||||||
SNMP.cc
|
PAC snmp.pac snmp-protocol.pac snmp-analyzer.pac
|
||||||
Plugin.cc
|
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac)
|
||||||
BIFS
|
|
||||||
types.bif
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
snmp.pac
|
|
||||||
snmp-protocol.pac
|
|
||||||
snmp-analyzer.pac
|
|
||||||
${PROJECT_SOURCE_DIR}/src/analyzer/protocol/asn1/asn1.pac)
|
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SOCKS
|
||||||
SOCKS
|
SOURCES SOCKS.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
SOCKS.cc
|
PAC socks.pac socks-protocol.pac socks-analyzer.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
socks.pac
|
|
||||||
socks-protocol.pac
|
|
||||||
socks-analyzer.pac)
|
|
||||||
|
|
|
@ -1,14 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SSH
|
||||||
SSH
|
SOURCES SSH.cc Plugin.cc
|
||||||
SOURCES
|
BIFS types.bif events.bif
|
||||||
SSH.cc
|
PAC ssh.pac ssh-analyzer.pac ssh-protocol.pac consts.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
types.bif
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
ssh.pac
|
|
||||||
ssh-analyzer.pac
|
|
||||||
ssh-protocol.pac
|
|
||||||
consts.pac)
|
|
||||||
|
|
|
@ -1,38 +1,19 @@
|
||||||
if (NOT ENABLE_SPICY_SSL)
|
if (NOT ENABLE_SPICY_SSL)
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SSL
|
||||||
SSL
|
SOURCES SSL.cc DTLS.cc Plugin.cc
|
||||||
SOURCES
|
BIFS types.bif events.bif functions.bif consts.bif
|
||||||
SSL.cc
|
PAC tls-handshake.pac tls-handshake-protocol.pac tls-handshake-analyzer.pac ssl-defs.pac
|
||||||
DTLS.cc
|
proc-certificate.pac tls-handshake-signed_certificate_timestamp.pac
|
||||||
Plugin.cc
|
PAC ssl.pac
|
||||||
BIFS
|
ssl-dtls-analyzer.pac
|
||||||
types.bif
|
ssl-analyzer.pac
|
||||||
events.bif
|
ssl-dtls-protocol.pac
|
||||||
functions.bif
|
ssl-protocol.pac
|
||||||
consts.bif
|
ssl-defs.pac
|
||||||
PAC
|
proc-certificate.pac
|
||||||
tls-handshake.pac
|
PAC dtls.pac ssl-dtls-analyzer.pac dtls-analyzer.pac ssl-dtls-protocol.pac
|
||||||
tls-handshake-protocol.pac
|
dtls-protocol.pac ssl-defs.pac)
|
||||||
tls-handshake-analyzer.pac
|
|
||||||
ssl-defs.pac
|
|
||||||
proc-certificate.pac
|
|
||||||
tls-handshake-signed_certificate_timestamp.pac
|
|
||||||
PAC
|
|
||||||
ssl.pac
|
|
||||||
ssl-dtls-analyzer.pac
|
|
||||||
ssl-analyzer.pac
|
|
||||||
ssl-dtls-protocol.pac
|
|
||||||
ssl-protocol.pac
|
|
||||||
ssl-defs.pac
|
|
||||||
proc-certificate.pac
|
|
||||||
PAC
|
|
||||||
dtls.pac
|
|
||||||
ssl-dtls-analyzer.pac
|
|
||||||
dtls-analyzer.pac
|
|
||||||
ssl-dtls-protocol.pac
|
|
||||||
dtls-protocol.pac
|
|
||||||
ssl-defs.pac)
|
|
||||||
else ()
|
else ()
|
||||||
add_subdirectory(spicy)
|
add_subdirectory(spicy)
|
||||||
zeek_add_plugin(Zeek SSL SOURCES Plugin.cc BIFS functions.bif)
|
zeek_add_plugin(Zeek SSL SOURCES Plugin.cc BIFS functions.bif)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
spicy_add_analyzer(NAME SSL SOURCES SSL.spicy SSL.evt support.cc)
|
spicy_add_analyzer(
|
||||||
|
NAME SSL
|
||||||
|
SOURCES SSL.spicy SSL.evt support.cc)
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek StreamEvent
|
||||||
StreamEvent
|
SOURCES StreamEvent.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
StreamEvent.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
spicy_add_analyzer(NAME Syslog SOURCES syslog.spicy syslog.evt LEGACY legacy)
|
spicy_add_analyzer(
|
||||||
|
NAME Syslog
|
||||||
|
SOURCES syslog.spicy syslog.evt LEGACY legacy)
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Syslog
|
||||||
Syslog
|
SOURCES Syslog.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
Syslog.cc
|
PAC syslog.pac syslog-analyzer.pac syslog-protocol.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
syslog.pac
|
|
||||||
syslog-analyzer.pac
|
|
||||||
syslog-protocol.pac)
|
|
||||||
|
|
|
@ -1,13 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek TCP
|
||||||
TCP
|
SOURCES TCP.cc TCP_Endpoint.cc TCP_Reassembler.cc ContentLine.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif types.bif functions.bif)
|
||||||
TCP.cc
|
|
||||||
TCP_Endpoint.cc
|
|
||||||
TCP_Reassembler.cc
|
|
||||||
ContentLine.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
types.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,18 +1,8 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek WebSocket
|
||||||
WebSocket
|
SOURCES WebSocket.cc Plugin.cc
|
||||||
SOURCES
|
BIFS consts.bif events.bif functions.bif types.bif
|
||||||
WebSocket.cc
|
PAC websocket.pac websocket-analyzer.pac websocket-protocol.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
consts.bif
|
|
||||||
events.bif
|
|
||||||
functions.bif
|
|
||||||
types.bif
|
|
||||||
PAC
|
|
||||||
websocket.pac
|
|
||||||
websocket-analyzer.pac
|
|
||||||
websocket-protocol.pac)
|
|
||||||
|
|
||||||
if (USE_SPICY_ANALYZERS)
|
if (USE_SPICY_ANALYZERS)
|
||||||
spicy_add_analyzer(NAME WebSocket SOURCES websocket.spicy websocket.evt unmask.cc)
|
spicy_add_analyzer(NAME WebSocket SOURCES websocket.spicy websocket.evt unmask.cc)
|
||||||
|
|
|
@ -1,12 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek XMPP
|
||||||
XMPP
|
SOURCES Plugin.cc XMPP.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
Plugin.cc
|
PAC xmpp.pac xmpp-analyzer.pac xmpp-protocol.pac)
|
||||||
XMPP.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
xmpp.pac
|
|
||||||
xmpp-analyzer.pac
|
|
||||||
xmpp-protocol.pac)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(Zeek ZIP SOURCES ZIP.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
Zeek ZIP
|
||||||
|
SOURCES ZIP.cc Plugin.cc)
|
||||||
|
|
|
@ -14,4 +14,6 @@ zeek_add_subdir_library(
|
||||||
store.bif)
|
store.bif)
|
||||||
|
|
||||||
# Small plugin shim to make the CLUSTER_BACKEND_BROKER enum value available.
|
# Small plugin shim to make the CLUSTER_BACKEND_BROKER enum value available.
|
||||||
zeek_add_plugin(Zeek Cluster_Backend_Broker SOURCES Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
Zeek Cluster_Backend_Broker
|
||||||
|
SOURCES Plugin.cc)
|
||||||
|
|
|
@ -3,17 +3,8 @@ list(APPEND CMAKE_MODULE_PATH "${CMAKE_CURRENT_SOURCE_DIR}/cmake")
|
||||||
find_package(ZeroMQ REQUIRED)
|
find_package(ZeroMQ REQUIRED)
|
||||||
|
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Cluster_Backend_ZeroMQ
|
||||||
Cluster_Backend_ZeroMQ
|
INCLUDE_DIRS ${CMAKE_CURRENT_SOURCE_DIR} ${CMAKE_CURRENT_BINARY_DIR} ${ZeroMQ_INCLUDE_DIRS}
|
||||||
INCLUDE_DIRS
|
DEPENDENCIES ${ZeroMQ_LIBRARIES}
|
||||||
${CMAKE_CURRENT_SOURCE_DIR}
|
SOURCES Plugin.cc ZeroMQ-Proxy.cc ZeroMQ.cc
|
||||||
${CMAKE_CURRENT_BINARY_DIR}
|
BIFS cluster_backend_zeromq.bif)
|
||||||
${ZeroMQ_INCLUDE_DIRS}
|
|
||||||
DEPENDENCIES
|
|
||||||
${ZeroMQ_LIBRARIES}
|
|
||||||
SOURCES
|
|
||||||
Plugin.cc
|
|
||||||
ZeroMQ-Proxy.cc
|
|
||||||
ZeroMQ.cc
|
|
||||||
BIFS
|
|
||||||
cluster_backend_zeromq.bif)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Zeek_Binary_Serializer
|
||||||
Zeek_Binary_Serializer
|
INCLUDE_DIRS ${CMAKE_CURRENT_SOURCE_DIR} ${CMAKE_CURRENT_BINARY_DIR}
|
||||||
INCLUDE_DIRS
|
SOURCES Plugin.cc Serializer.cc)
|
||||||
${CMAKE_CURRENT_SOURCE_DIR}
|
|
||||||
${CMAKE_CURRENT_BINARY_DIR}
|
|
||||||
SOURCES
|
|
||||||
Plugin.cc
|
|
||||||
Serializer.cc)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Cluster_Serializer_Binary_Serialization_Format
|
||||||
Cluster_Serializer_Binary_Serialization_Format
|
INCLUDE_DIRS ${CMAKE_CURRENT_SOURCE_DIR} ${CMAKE_CURRENT_BINARY_DIR}
|
||||||
INCLUDE_DIRS
|
SOURCES Plugin.cc Serializer.cc)
|
||||||
${CMAKE_CURRENT_SOURCE_DIR}
|
|
||||||
${CMAKE_CURRENT_BINARY_DIR}
|
|
||||||
SOURCES
|
|
||||||
Plugin.cc
|
|
||||||
Serializer.cc)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek FileDataEvent
|
||||||
FileDataEvent
|
SOURCES DataEvent.cc Plugin.cc
|
||||||
SOURCES
|
INCLUDE_DIRS "${CMAKE_CURRENT_SOURCE_DIR}")
|
||||||
DataEvent.cc
|
|
||||||
Plugin.cc
|
|
||||||
INCLUDE_DIRS
|
|
||||||
"${CMAKE_CURRENT_SOURCE_DIR}")
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek FileEntropy
|
||||||
FileEntropy
|
SOURCES Entropy.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
Entropy.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek FileExtract
|
||||||
FileExtract
|
SOURCES Extract.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
Extract.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek FileHash
|
||||||
FileHash
|
SOURCES Hash.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
Hash.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1,15 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek PE
|
||||||
PE
|
SOURCES PE.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif
|
||||||
PE.cc
|
PAC pe.pac pe-analyzer.pac pe-file-headers.pac pe-file-idata.pac pe-file.pac pe-file-types.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
PAC
|
|
||||||
pe.pac
|
|
||||||
pe-analyzer.pac
|
|
||||||
pe-file-headers.pac
|
|
||||||
pe-file-idata.pac
|
|
||||||
pe-file.pac
|
|
||||||
pe-file-types.pac)
|
|
||||||
|
|
|
@ -1,16 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek X509
|
||||||
X509
|
SOURCES X509Common.cc X509.cc OCSP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif types.bif functions.bif ocsp_events.bif
|
||||||
X509Common.cc
|
PAC x509-extension.pac x509-signed_certificate_timestamp.pac)
|
||||||
X509.cc
|
|
||||||
OCSP.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
types.bif
|
|
||||||
functions.bif
|
|
||||||
ocsp_events.bif
|
|
||||||
PAC
|
|
||||||
x509-extension.pac
|
|
||||||
x509-signed_certificate_timestamp.pac)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek AsciiReader
|
||||||
AsciiReader
|
SOURCES Ascii.cc Plugin.cc
|
||||||
SOURCES
|
BIFS ascii.bif)
|
||||||
Ascii.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
ascii.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek BenchmarkReader
|
||||||
BenchmarkReader
|
SOURCES Benchmark.cc Plugin.cc
|
||||||
SOURCES
|
BIFS benchmark.bif)
|
||||||
Benchmark.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
benchmark.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek BinaryReader
|
||||||
BinaryReader
|
SOURCES Binary.cc Plugin.cc
|
||||||
SOURCES
|
BIFS binary.bif)
|
||||||
Binary.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
binary.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek ConfigReader
|
||||||
ConfigReader
|
SOURCES Config.cc Plugin.cc
|
||||||
SOURCES
|
BIFS config.bif)
|
||||||
Config.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
config.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek RawReader
|
||||||
RawReader
|
SOURCES Raw.cc Plugin.cc
|
||||||
SOURCES
|
BIFS raw.bif)
|
||||||
Raw.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
raw.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SQLiteReader
|
||||||
SQLiteReader
|
SOURCES SQLite.cc Plugin.cc
|
||||||
SOURCES
|
BIFS sqlite.bif)
|
||||||
SQLite.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
sqlite.bif)
|
|
||||||
|
|
|
@ -1,4 +1,6 @@
|
||||||
zeek_add_plugin(Zeek Pcap SOURCES Source.cc Dumper.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
Zeek Pcap
|
||||||
|
SOURCES Source.cc Dumper.cc Plugin.cc)
|
||||||
|
|
||||||
# Treat BIFs as builtin (alternative mode).
|
# Treat BIFs as builtin (alternative mode).
|
||||||
bif_target(pcap.bif)
|
bif_target(pcap.bif)
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek AsciiWriter
|
||||||
AsciiWriter
|
SOURCES Ascii.cc Plugin.cc
|
||||||
SOURCES
|
BIFS ascii.bif)
|
||||||
Ascii.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
ascii.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek NoneWriter
|
||||||
NoneWriter
|
SOURCES None.cc Plugin.cc
|
||||||
SOURCES
|
BIFS none.bif)
|
||||||
None.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
none.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek SQLiteWriter
|
||||||
SQLiteWriter
|
SOURCES SQLite.cc Plugin.cc
|
||||||
SOURCES
|
BIFS sqlite.bif)
|
||||||
SQLite.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
sqlite.bif)
|
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek ARP
|
||||||
ARP
|
SOURCES ARP.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
ARP.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(Zeek AYIYA SOURCES AYIYA.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
Zeek AYIYA
|
||||||
|
SOURCES AYIYA.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer Ethernet SOURCES Ethernet.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer Ethernet
|
||||||
|
SOURCES Ethernet.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer FDDI SOURCES FDDI.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer FDDI
|
||||||
|
SOURCES FDDI.cc Plugin.cc)
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Geneve
|
||||||
Geneve
|
SOURCES Geneve.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
Geneve.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer GRE SOURCES GRE.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer GRE
|
||||||
|
SOURCES GRE.cc Plugin.cc)
|
||||||
|
|
|
@ -1,13 +1,5 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek GTPv1
|
||||||
GTPv1
|
SOURCES GTPv1.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif
|
||||||
GTPv1.cc
|
PAC gtpv1.pac gtpv1-protocol.pac gtpv1-analyzer.pac)
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif
|
|
||||||
PAC
|
|
||||||
gtpv1.pac
|
|
||||||
gtpv1-protocol.pac
|
|
||||||
gtpv1-analyzer.pac)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek ICMP
|
||||||
ICMP
|
SOURCES ICMP.cc ICMPSessionAdapter.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
ICMP.cc
|
|
||||||
ICMPSessionAdapter.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer IEEE802_11 SOURCES IEEE802_11.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer IEEE802_11
|
||||||
|
SOURCES IEEE802_11.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer IEEE802_11_Radio SOURCES IEEE802_11_Radio.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer IEEE802_11_Radio
|
||||||
|
SOURCES IEEE802_11_Radio.cc Plugin.cc)
|
||||||
|
|
|
@ -1,8 +1,3 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
PacketAnalyzer
|
PacketAnalyzer IP
|
||||||
IP
|
SOURCES IP.cc IPBasedAnalyzer.cc SessionAdapter.cc Plugin.cc)
|
||||||
SOURCES
|
|
||||||
IP.cc
|
|
||||||
IPBasedAnalyzer.cc
|
|
||||||
SessionAdapter.cc
|
|
||||||
Plugin.cc)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer IPTunnel SOURCES IPTunnel.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer IPTunnel
|
||||||
|
SOURCES IPTunnel.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer LinuxSLL SOURCES LinuxSLL.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer LinuxSLL
|
||||||
|
SOURCES LinuxSLL.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer LinuxSLL2 SOURCES LinuxSLL2.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer LinuxSLL2
|
||||||
|
SOURCES LinuxSLL2.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer LLC SOURCES LLC.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer LLC
|
||||||
|
SOURCES LLC.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer MPLS SOURCES MPLS.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer MPLS
|
||||||
|
SOURCES MPLS.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer NFLog SOURCES NFLog.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer NFLog
|
||||||
|
SOURCES NFLog.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer Novell_802_3 SOURCES Novell_802_3.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer Novell_802_3
|
||||||
|
SOURCES Novell_802_3.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer Null SOURCES Null.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer Null
|
||||||
|
SOURCES Null.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer PPP SOURCES PPP.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer PPP
|
||||||
|
SOURCES PPP.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer PPPSerial SOURCES PPPSerial.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer PPPSerial
|
||||||
|
SOURCES PPPSerial.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer PPPoE SOURCES PPPoE.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer PPPoE
|
||||||
|
SOURCES PPPoE.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer Root SOURCES Root.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer Root
|
||||||
|
SOURCES Root.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer Skip SOURCES Skip.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer Skip
|
||||||
|
SOURCES Skip.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer SNAP SOURCES SNAP.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer SNAP
|
||||||
|
SOURCES SNAP.cc Plugin.cc)
|
||||||
|
|
|
@ -1,8 +1,3 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
PacketAnalyzer
|
PacketAnalyzer TCP_PKT
|
||||||
TCP_PKT
|
SOURCES TCP.cc TCPSessionAdapter.cc Plugin.cc Stats.cc)
|
||||||
SOURCES
|
|
||||||
TCP.cc
|
|
||||||
TCPSessionAdapter.cc
|
|
||||||
Plugin.cc
|
|
||||||
Stats.cc)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek Teredo
|
||||||
Teredo
|
SOURCES Teredo.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif functions.bif)
|
||||||
Teredo.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif
|
|
||||||
functions.bif)
|
|
||||||
|
|
|
@ -1,9 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek UDP
|
||||||
UDP
|
SOURCES UDP.cc UDPSessionAdapter.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
UDP.cc
|
|
||||||
UDPSessionAdapter.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(Zeek UnknownIP SOURCES UnknownIPTransport.cc UnknownIPSessionAdapter.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
Zeek UnknownIP
|
||||||
|
SOURCES UnknownIPTransport.cc UnknownIPSessionAdapter.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer VLAN SOURCES VLAN.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer VLAN
|
||||||
|
SOURCES VLAN.cc Plugin.cc)
|
||||||
|
|
|
@ -1 +1,3 @@
|
||||||
zeek_add_plugin(PacketAnalyzer VNTag SOURCES VNTag.cc Plugin.cc)
|
zeek_add_plugin(
|
||||||
|
PacketAnalyzer VNTag
|
||||||
|
SOURCES VNTag.cc Plugin.cc)
|
||||||
|
|
|
@ -1,8 +1,4 @@
|
||||||
zeek_add_plugin(
|
zeek_add_plugin(
|
||||||
Zeek
|
Zeek VXLAN
|
||||||
VXLAN
|
SOURCES VXLAN.cc Plugin.cc
|
||||||
SOURCES
|
BIFS events.bif)
|
||||||
VXLAN.cc
|
|
||||||
Plugin.cc
|
|
||||||
BIFS
|
|
||||||
events.bif)
|
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue