mirror of
https://github.com/zeek/zeek.git
synced 2025-10-08 09:38:19 +00:00

* topic/robin/intel-framework-merge: (22 commits) Fixing tests after intel-framework merge. Extracting URLs from message bodies over SMTP and sending them to Intel framework. Small comment updates in the Intel framework CIF support. Intelligence framework documentation first draft. Only the manager tries to read files with the input framework now. Initial support for Bro's Intel framework with the Collective Intelligence Framework. Initial API for Intel framework is complete. Fixed an issue with cluster data distribution. Updating some intel framework test baselines. Reworked cluster intelligence data distribution mechanism and fixed tests. Lots more intelligence checking in SMTP traffic. Added intelligence check for "Received" path checking and a bit of reshuffling. Added sources to the intel log. Fixing a problem with intel distribution on clusters. Updated intel framework test to include matching. Restructuring the scripts that feed data into the intel framework slightly. One test for cluster transparency of the intel framework. Fixed a cluster support bug. Intelligence framework checkpoint Major updates to fix the Intel framework API. ... Closes #914.
77 lines
2.9 KiB
Text
77 lines
2.9 KiB
Text
# This file loads ALL policy scripts that are part of the Bro distribution.
|
|
#
|
|
# This is rarely makes sense, and is for testing only.
|
|
#
|
|
# Note that we have a unit test that makes sure that all policy files shipped are
|
|
# actually loaded here. If we have files that are part of the distribution yet
|
|
# can't be loaded here, these must still be listed here with their load command
|
|
# commented out.
|
|
|
|
# The base/ scripts are all loaded by default and not included here.
|
|
|
|
# @load frameworks/communication/listen.bro
|
|
# @load frameworks/control/controllee.bro
|
|
# @load frameworks/control/controller.bro
|
|
@load frameworks/dpd/detect-protocols.bro
|
|
@load frameworks/dpd/packet-segment-logging.bro
|
|
@load frameworks/intel/__load__.bro
|
|
@load frameworks/intel/conn-established.bro
|
|
@load frameworks/intel/dns.bro
|
|
@load frameworks/intel/http-host-header.bro
|
|
@load frameworks/intel/http-url.bro
|
|
@load frameworks/intel/http-user-agents.bro
|
|
@load frameworks/intel/smtp-url-extraction.bro
|
|
@load frameworks/intel/smtp.bro
|
|
@load frameworks/intel/ssl.bro
|
|
@load frameworks/intel/where-locations.bro
|
|
@load frameworks/metrics/conn-example.bro
|
|
@load frameworks/metrics/http-example.bro
|
|
@load frameworks/metrics/ssl-example.bro
|
|
@load frameworks/software/version-changes.bro
|
|
@load frameworks/software/vulnerable.bro
|
|
@load integration/barnyard2/__load__.bro
|
|
@load integration/barnyard2/main.bro
|
|
@load integration/barnyard2/types.bro
|
|
@load integration/collective-intel/__load__.bro
|
|
@load integration/collective-intel/main.bro
|
|
@load misc/analysis-groups.bro
|
|
@load misc/capture-loss.bro
|
|
@load misc/loaded-scripts.bro
|
|
@load misc/profiling.bro
|
|
@load misc/stats.bro
|
|
@load misc/trim-trace-file.bro
|
|
@load protocols/conn/known-hosts.bro
|
|
@load protocols/conn/known-services.bro
|
|
@load protocols/conn/weirds.bro
|
|
@load protocols/dns/auth-addl.bro
|
|
@load protocols/dns/detect-external-names.bro
|
|
@load protocols/ftp/detect.bro
|
|
@load protocols/ftp/software.bro
|
|
@load protocols/http/detect-MHR.bro
|
|
@load protocols/http/detect-sqli.bro
|
|
@load protocols/http/detect-webapps.bro
|
|
@load protocols/http/header-names.bro
|
|
@load protocols/http/software-browser-plugins.bro
|
|
@load protocols/http/software.bro
|
|
@load protocols/http/var-extraction-cookies.bro
|
|
@load protocols/http/var-extraction-uri.bro
|
|
@load protocols/modbus/known-masters-slaves.bro
|
|
@load protocols/modbus/track-memmap.bro
|
|
@load protocols/smtp/blocklists.bro
|
|
@load protocols/smtp/detect-suspicious-orig.bro
|
|
@load protocols/smtp/software.bro
|
|
@load protocols/ssh/detect-bruteforcing.bro
|
|
@load protocols/ssh/geo-data.bro
|
|
@load protocols/ssh/interesting-hostnames.bro
|
|
@load protocols/ssh/software.bro
|
|
@load protocols/ssl/cert-hash.bro
|
|
@load protocols/ssl/expiring-certs.bro
|
|
@load protocols/ssl/extract-certs-pem.bro
|
|
@load protocols/ssl/known-certs.bro
|
|
@load protocols/ssl/validate-certs.bro
|
|
@load tuning/__load__.bro
|
|
@load tuning/defaults/__load__.bro
|
|
@load tuning/defaults/packet-fragments.bro
|
|
@load tuning/defaults/warnings.bro
|
|
@load tuning/logs-to-elasticsearch.bro
|
|
@load tuning/track-all-assets.bro
|