mirror of
https://github.com/zeek/zeek.git
synced 2025-10-04 23:58:20 +00:00
This signature is relevant for process dumps on Windows that could be extracted by various tools. The unencrypted transmission of the dump of a critical system process (for example, lsass.exe) via network would be detected by this rule. |
||
|---|---|---|
| .. | ||
| magic | ||
| __load__.zeek | ||
| main.zeek | ||
| README | ||
The file analysis framework provides an interface for driving the analysis of files, possibly independent of any network protocol over which they're transported.