zeek/scripts/policy/frameworks/intel/seen
Seth Hall d89ee3cee0 Change the meaning of some email fields.
We now extract email addresses in the fields that one would expect
to contain addresses.  This makes further downstream processing of
these fields easier like log analysis or using these fields in the
Intel framework.  The primary downside is that any other content
in these fields is no longer available such as full name and any
group information.  I believe the simplification of the content in
these fields is worth the change.

Added "cc" to the script that feeds information from SMTP into the
Intel framework.

A new script for email handling utility functions has been created
as a side effect of these changes.
2016-06-15 10:32:06 -04:00
..
__load__.bro X509 file analyzer nearly done. Verification and most other policy scripts 2014-03-03 17:07:50 -08:00
conn-established.bro Some script reorg and a new intel extension script. 2013-07-29 16:40:16 -04:00
dns.bro Some script reorg and a new intel extension script. 2013-07-29 16:40:16 -04:00
file-hashes.bro Add file name support to intel framework. 2013-08-13 13:21:31 -04:00
file-names.bro Add file name support to intel framework. 2013-08-13 13:21:31 -04:00
http-headers.bro Deprecate split* family of BIFs. 2015-01-21 15:34:42 -06:00
http-url.bro Some script reorg and a new intel extension script. 2013-07-29 16:40:16 -04:00
pubkey-hashes.bro SSH: Intel framework integration (PUBKEY_HASH) 2015-03-17 12:33:09 -04:00
README Add more script package README files 2013-10-23 16:36:14 -05:00
smtp-url-extraction.bro Merge remote-tracking branch 'origin/topic/seth/faf-updates' 2013-07-29 14:21:52 -07:00
smtp.bro Change the meaning of some email fields. 2016-06-15 10:32:06 -04:00
ssl.bro Use our new features to send the CN and SAN fields of certificates to 2015-03-03 17:15:24 -08:00
where-locations.bro Change the meaning of some email fields. 2016-06-15 10:32:06 -04:00
x509.bro Merge remote-tracking branch 'origin/topic/johanna/x509-cn' 2015-03-04 12:31:34 -08:00

Scripts that send data to the intelligence framework.