zeek/scripts/base/protocols
Seth Hall d89ee3cee0 Change the meaning of some email fields.
We now extract email addresses in the fields that one would expect
to contain addresses.  This makes further downstream processing of
these fields easier like log analysis or using these fields in the
Intel framework.  The primary downside is that any other content
in these fields is no longer available such as full name and any
group information.  I believe the simplification of the content in
these fields is worth the change.

Added "cc" to the script that feeds information from SMTP into the
Intel framework.

A new script for email handling utility functions has been created
as a side effect of these changes.
2016-06-15 10:32:06 -04:00
..
conn Merge remote-tracking branch 'origin/topic/vladg/bit-1466' 2015-08-25 07:45:36 -07:00
dhcp Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00
dnp3 Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00
dns Merge remote-tracking branch 'origin/topic/jsiwek/bit-1324' 2015-03-23 10:35:30 -07:00
ftp Fix reporter errors with GridFTP traffic. 2015-06-08 09:42:06 -07:00
http Merge branch 'patch-3' of https://github.com/aeppert/bro 2016-01-15 10:35:57 -08:00
irc File API updates complete. 2015-04-20 10:46:48 -04:00
krb Add missing documentation on the "Bro Package Index" page 2015-06-02 10:00:00 -05:00
modbus Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00
mysql Add missing documentation on the "Bro Package Index" page 2015-06-02 10:00:00 -05:00
pop3 Add README files for base/protocols 2013-10-17 12:47:32 -05:00
radius Add missing documentation on the "Bro Package Index" page 2015-06-02 10:00:00 -05:00
rdp Add missing documentation on the "Bro Package Index" page 2015-06-02 10:00:00 -05:00
sip NOTIFY is a valid SIP message per RFC3265 2016-01-08 17:11:14 -05:00
smtp Change the meaning of some email fields. 2016-06-15 10:32:06 -04:00
snmp Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00
socks Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00
ssh Add missing documentation on the "Bro Package Index" page 2015-06-02 10:00:00 -05:00
ssl Extend ssl dpd signature to allow alert before server_hello. 2015-10-22 13:36:21 -07:00
syslog Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00
tunnels Make Teredo DPD signature more precise. 2015-08-12 17:16:09 -07:00