Corelight Sensors come pre-loaded with a set of the most popular and useful Zeek / Bro packages (a Zeek package is a script with metadata), to get you up and running in minutes. But sometimes you want to add extra functionality or customization. These Zeek scripts have been vetted and tested for performance by the Corelight team.
Detects HTTP stalling DoS attacks, such as Slowloris.Download
Logs the top DNS requests at a configurable interval (15 min. default).Download
Generates SSL client fingerprints and logs them as a new field in the ssl.log.Download
Logs files without known MIME types.Download