mirror of
https://github.com/zeek/zeek.git
synced 2025-10-10 10:38:20 +00:00
![]() The extension mechanism is basically the one that Seth introduced with his intel extensions. The main difference lies in using a hook instead of an event. An example policy implements whitelisting. |
||
---|---|---|
.. | ||
seen | ||
do_notice.bro | ||
whitelist.bro |