No description
Find a file
Seth Hall bbedb73a45 Huge updates to the RDP analyzer from Josh Liburdi.
- More data pulled into scriptland.
  - Logs expanded with client screen resolution and desired color depth.
  - Values in UTF-16 on the wire are converted to UTF-8 before being
    sent to scriptland.
  - If the RDP turns into SSL records, we now pass data that appears
    to be SSL to the PIA analyzer.
  - If RDP uses native encryption with X.509 certs we pass those
    certs to the files framework and the base scripts pass them forward
    to the X.509 analyzer.
  - Lots of cleanup and adjustment to fit the documented protocol
    a bit better.
  - Cleaned up the DPD signatures.
  - Moved to flowunit instead of datagram.
  - Added tests.
2015-03-04 13:12:03 -05:00
aux Updating submodule(s). 2015-02-13 18:04:17 -06:00
cmake@1316c07f70 Updating submodule(s). 2014-11-03 10:19:48 -06:00
doc Merge remote-tracking branch 'origin/topic/jsiwek/deprecation' 2015-01-30 14:37:05 -08:00
man Improve man page for Bro 2014-12-04 23:46:03 -06:00
pkg Add configure options to fine tune local state dirs used by BroControl. 2014-10-30 17:11:46 -05:00
scripts Huge updates to the RDP analyzer from Josh Liburdi. 2015-03-04 13:12:03 -05:00
src Huge updates to the RDP analyzer from Josh Liburdi. 2015-03-04 13:12:03 -05:00
testing Huge updates to the RDP analyzer from Josh Liburdi. 2015-03-04 13:12:03 -05:00
.gitignore Ignore tmp dir. 2011-10-25 19:59:25 -07:00
.gitmodules Move DataSeries and ElasticSearch into plugins. 2014-08-08 18:32:21 -07:00
bro-path-dev.in Flesh out Broxygen doc-gathering skeleton. 2013-10-22 14:45:47 -05:00
CHANGES Merge remote-tracking branch 'origin/topic/jsiwek/socks-authentication' 2015-02-13 09:15:50 -06:00
CMakeLists.txt Increase minimum required CMake version to 2.8. 2015-01-08 13:11:17 -06:00
config.h.in Fix build on systems that already have ntohll/htonll 2014-08-22 19:56:27 -05:00
configure Add configure options to fine tune local state dirs used by BroControl. 2014-10-30 17:11:46 -05:00
COPYING Updating copyright notice. 2013-10-07 17:06:38 -07:00
INSTALL Merge remote-tracking branch 'origin/topic/documentation' 2013-08-31 16:07:44 -07:00
Makefile Changing Makefile's test-all to run test-all for broctl. 2014-12-31 09:19:09 -08:00
NEWS Merge remote-tracking branch 'origin/topic/jsiwek/deprecation' 2015-01-30 14:37:05 -08:00
README Updating README with download/git information. 2013-10-25 15:06:13 -07:00
VERSION Merge remote-tracking branch 'origin/topic/jsiwek/socks-authentication' 2015-02-13 09:15:50 -06:00

============================
Bro Network Security Monitor
============================

Bro is a powerful framework for network analysis and security
monitoring. Please see the INSTALL file for installation instructions
and pointers for getting started. NEWS contains release notes for the
current version, and CHANGES has the complete history of changes.
Please see COPYING for licensing information.

You can download source and binary releases on:

    http://www.bro.org/download

To get the current development version, clone our master git
repository:

    git clone --recursive git://git.bro.org/bro

For more documentation, research publications, and community contact
information, please see Bro's home page:

    http://www.bro.org


On behalf of the Bro Development Team,

Vern Paxson & Robin Sommer,
International Computer Science Institute &
Lawrence Berkeley National Laboratory
vern@icir.org / robin@icir.org