mirror of
https://github.com/zeek/zeek.git
synced 2025-10-05 16:18:19 +00:00
Enable GridFTP detection by default. Track/log SSL client certs.
In the *service* field of connection records, GridFTP control channels are labeled as "gridftp" and data channels as "gridftp-data". Added *client_subject* and *client_issuer_subject* as &log'd fields to SSL::Info record. Also added *client_cert* and *client_cert_chain* fields to track client cert chain.
This commit is contained in:
parent
d0b249a731
commit
e34f6d9e3b
15 changed files with 238 additions and 132 deletions
|
@ -69,6 +69,7 @@ rest_target(${psd} base/protocols/conn/polling.bro)
|
|||
rest_target(${psd} base/protocols/dns/consts.bro)
|
||||
rest_target(${psd} base/protocols/dns/main.bro)
|
||||
rest_target(${psd} base/protocols/ftp/file-extract.bro)
|
||||
rest_target(${psd} base/protocols/ftp/gridftp.bro)
|
||||
rest_target(${psd} base/protocols/ftp/main.bro)
|
||||
rest_target(${psd} base/protocols/ftp/utils-commands.bro)
|
||||
rest_target(${psd} base/protocols/http/file-extract.bro)
|
||||
|
@ -123,7 +124,6 @@ rest_target(${psd} policy/protocols/conn/weirds.bro)
|
|||
rest_target(${psd} policy/protocols/dns/auth-addl.bro)
|
||||
rest_target(${psd} policy/protocols/dns/detect-external-names.bro)
|
||||
rest_target(${psd} policy/protocols/ftp/detect.bro)
|
||||
rest_target(${psd} policy/protocols/ftp/gridftp-data-detection.bro)
|
||||
rest_target(${psd} policy/protocols/ftp/software.bro)
|
||||
rest_target(${psd} policy/protocols/http/detect-MHR.bro)
|
||||
rest_target(${psd} policy/protocols/http/detect-intel.bro)
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue