/usr/share/bro/policy/frameworks/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/communication/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/communication/listen.bro
|
text/plain
|
root:root
|
0o644
|
331 bytes
|
/usr/share/bro/policy/frameworks/control/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/control/controllee.bro
|
text/plain
|
root:root
|
0o644
|
1.9 KB
|
/usr/share/bro/policy/frameworks/control/controller.bro
|
text/plain
|
root:root
|
0o644
|
3.1 KB
|
/usr/share/bro/policy/frameworks/dpd/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/dpd/detect-protocols.bro
|
text/plain
|
root:root
|
0o644
|
6.2 KB
|
/usr/share/bro/policy/frameworks/dpd/packet-segment-logging.bro
|
text/plain
|
root:root
|
0o644
|
926 bytes
|
/usr/share/bro/policy/frameworks/files/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/files/detect-MHR.bro
|
text/plain
|
root:root
|
0o644
|
2.6 KB
|
/usr/share/bro/policy/frameworks/files/entropy-test-all-files.bro
|
text/plain
|
root:root
|
0o644
|
385 bytes
|
/usr/share/bro/policy/frameworks/files/extract-all-files.bro
|
text/plain
|
root:root
|
0o644
|
141 bytes
|
/usr/share/bro/policy/frameworks/files/hash-all-files.bro
|
text/plain
|
root:root
|
0o644
|
197 bytes
|
/usr/share/bro/policy/frameworks/intel/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/intel/do_expire.bro
|
text/plain
|
root:root
|
0o644
|
293 bytes
|
/usr/share/bro/policy/frameworks/intel/do_notice.bro
|
text/plain
|
root:root
|
0o644
|
1.8 KB
|
/usr/share/bro/policy/frameworks/intel/seen/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/intel/seen/__load__.bro
|
text/plain
|
root:root
|
0o644
|
202 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/conn-established.bro
|
text/plain
|
root:root
|
0o644
|
326 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/dns.bro
|
text/plain
|
root:root
|
0o644
|
290 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/file-hashes.bro
|
text/plain
|
root:root
|
0o644
|
321 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/file-names.bro
|
text/plain
|
root:root
|
0o644
|
274 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/http-headers.bro
|
text/plain
|
root:root
|
0o644
|
1.4 KB
|
/usr/share/bro/policy/frameworks/intel/seen/http-url.bro
|
text/plain
|
root:root
|
0o644
|
353 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/pubkey-hashes.bro
|
text/plain
|
root:root
|
0o644
|
295 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/smtp-url-extraction.bro
|
text/plain
|
root:root
|
0o644
|
630 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/smtp.bro
|
text/plain
|
root:root
|
0o644
|
2.1 KB
|
/usr/share/bro/policy/frameworks/intel/seen/ssl.bro
|
text/plain
|
root:root
|
0o644
|
786 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/where-locations.bro
|
text/plain
|
root:root
|
0o644
|
596 bytes
|
/usr/share/bro/policy/frameworks/intel/seen/x509.bro
|
text/plain
|
root:root
|
0o644
|
1.2 KB
|
/usr/share/bro/policy/frameworks/intel/whitelist.bro
|
text/plain
|
root:root
|
0o644
|
511 bytes
|
/usr/share/bro/policy/frameworks/packet-filter/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/packet-filter/shunt.bro
|
text/plain
|
root:root
|
0o644
|
4.6 KB
|
/usr/share/bro/policy/frameworks/signatures/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/signatures/detect-windows-shells.sig
|
text/plain
|
root:root
|
0o644
|
476 bytes
|
/usr/share/bro/policy/frameworks/software/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/frameworks/software/version-changes.bro
|
text/plain
|
root:root
|
0o644
|
1.3 KB
|
/usr/share/bro/policy/frameworks/software/vulnerable.bro
|
text/plain
|
root:root
|
0o644
|
4.3 KB
|
/usr/share/bro/policy/frameworks/software/windows-version-detection.bro
|
text/plain
|
root:root
|
0o644
|
5.3 KB
|
/usr/share/bro/policy/integration/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/integration/barnyard2/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/integration/barnyard2/__load__.bro
|
text/plain
|
root:root
|
0o644
|
27 bytes
|
/usr/share/bro/policy/integration/barnyard2/main.bro
|
text/plain
|
root:root
|
0o644
|
1.9 KB
|
/usr/share/bro/policy/integration/barnyard2/types.bro
|
text/plain
|
root:root
|
0o644
|
1.1 KB
|
/usr/share/bro/policy/integration/collective-intel/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/integration/collective-intel/__load__.bro
|
text/plain
|
root:root
|
0o644
|
12 bytes
|
/usr/share/bro/policy/integration/collective-intel/main.bro
|
text/plain
|
root:root
|
0o644
|
519 bytes
|
/usr/share/bro/policy/misc/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/misc/capture-loss.bro
|
text/plain
|
root:root
|
0o644
|
3.0 KB
|
/usr/share/bro/policy/misc/detect-traceroute/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/misc/detect-traceroute/__load__.bro
|
text/plain
|
root:root
|
0o644
|
12 bytes
|
/usr/share/bro/policy/misc/detect-traceroute/detect-low-ttls.sig
|
text/plain
|
root:root
|
0o644
|
148 bytes
|
/usr/share/bro/policy/misc/detect-traceroute/main.bro
|
text/plain
|
root:root
|
0o644
|
4.1 KB
|
/usr/share/bro/policy/misc/dump-events.bro
|
text/plain
|
root:root
|
0o644
|
1011 bytes
|
/usr/share/bro/policy/misc/known-devices.bro
|
text/plain
|
root:root
|
0o644
|
1.5 KB
|
/usr/share/bro/policy/misc/load-balancing.bro
|
text/plain
|
root:root
|
0o644
|
4.0 KB
|
/usr/share/bro/policy/misc/loaded-scripts.bro
|
text/plain
|
root:root
|
0o644
|
837 bytes
|
/usr/share/bro/policy/misc/profiling.bro
|
text/plain
|
root:root
|
0o644
|
409 bytes
|
/usr/share/bro/policy/misc/scan.bro
|
text/plain
|
root:root
|
0o644
|
6.6 KB
|
/usr/share/bro/policy/misc/stats.bro
|
text/plain
|
root:root
|
0o644
|
5.2 KB
|
/usr/share/bro/policy/misc/trim-trace-file.bro
|
text/plain
|
root:root
|
0o644
|
1010 bytes
|
/usr/share/bro/policy/protocols/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/conn/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/conn/known-hosts.bro
|
text/plain
|
root:root
|
0o644
|
1.9 KB
|
/usr/share/bro/policy/protocols/conn/known-services.bro
|
text/plain
|
root:root
|
0o644
|
3.3 KB
|
/usr/share/bro/policy/protocols/conn/mac-logging.bro
|
text/plain
|
root:root
|
0o644
|
722 bytes
|
/usr/share/bro/policy/protocols/conn/vlan-logging.bro
|
text/plain
|
root:root
|
0o644
|
663 bytes
|
/usr/share/bro/policy/protocols/conn/weirds.bro
|
text/plain
|
root:root
|
0o644
|
1.1 KB
|
/usr/share/bro/policy/protocols/dhcp/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/dhcp/known-devices-and-hostnames.bro
|
text/plain
|
root:root
|
0o644
|
903 bytes
|
/usr/share/bro/policy/protocols/dns/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/dns/auth-addl.bro
|
text/plain
|
root:root
|
0o644
|
1.1 KB
|
/usr/share/bro/policy/protocols/dns/detect-external-names.bro
|
text/plain
|
root:root
|
0o644
|
1.1 KB
|
/usr/share/bro/policy/protocols/ftp/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/ftp/detect-bruteforcing.bro
|
text/plain
|
root:root
|
0o644
|
2.2 KB
|
/usr/share/bro/policy/protocols/ftp/detect.bro
|
text/plain
|
root:root
|
0o644
|
800 bytes
|
/usr/share/bro/policy/protocols/ftp/software.bro
|
text/plain
|
root:root
|
0o644
|
621 bytes
|
/usr/share/bro/policy/protocols/http/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/http/detect-sqli.bro
|
text/plain
|
root:root
|
0o644
|
5.8 KB
|
/usr/share/bro/policy/protocols/http/detect-webapps.bro
|
text/plain
|
root:root
|
0o644
|
1.6 KB
|
/usr/share/bro/policy/protocols/http/detect-webapps.sig
|
text/html
|
root:root
|
0o644
|
2.4 KB
|
/usr/share/bro/policy/protocols/http/header-names.bro
|
text/plain
|
root:root
|
0o644
|
1.4 KB
|
/usr/share/bro/policy/protocols/http/software-browser-plugins.bro
|
text/plain
|
root:root
|
0o644
|
2.4 KB
|
/usr/share/bro/policy/protocols/http/software.bro
|
text/plain
|
root:root
|
0o644
|
1.3 KB
|
/usr/share/bro/policy/protocols/http/var-extraction-cookies.bro
|
text/plain
|
root:root
|
0o644
|
459 bytes
|
/usr/share/bro/policy/protocols/http/var-extraction-uri.bro
|
text/plain
|
root:root
|
0o644
|
446 bytes
|
/usr/share/bro/policy/protocols/modbus/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/modbus/known-masters-slaves.bro
|
text/plain
|
root:root
|
0o644
|
1.6 KB
|
/usr/share/bro/policy/protocols/modbus/track-memmap.bro
|
text/plain
|
root:root
|
0o644
|
3.2 KB
|
/usr/share/bro/policy/protocols/mysql/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/mysql/software.bro
|
text/plain
|
root:root
|
0o644
|
410 bytes
|
/usr/share/bro/policy/protocols/rdp/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/rdp/indicate_ssl.bro
|
text/plain
|
root:root
|
0o644
|
396 bytes
|
/usr/share/bro/policy/protocols/smb/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/smb/__load__.bro
|
text/plain
|
root:root
|
0o644
|
111 bytes
|
/usr/share/bro/policy/protocols/smb/dpd.sig
|
text/plain
|
root:root
|
0o644
|
82 bytes
|
/usr/share/bro/policy/protocols/smb/files.bro
|
text/plain
|
root:root
|
0o644
|
2.2 KB
|
/usr/share/bro/policy/protocols/smb/main.bro
|
text/plain
|
root:root
|
0o644
|
7.5 KB
|
/usr/share/bro/policy/protocols/smb/smb1-main.bro
|
text/plain
|
root:root
|
0o644
|
10.5 KB
|
/usr/share/bro/policy/protocols/smb/smb2-main.bro
|
text/plain
|
root:root
|
0o644
|
9.3 KB
|
/usr/share/bro/policy/protocols/smtp/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/smtp/blocklists.bro
|
text/plain
|
root:root
|
0o644
|
1.8 KB
|
/usr/share/bro/policy/protocols/smtp/detect-suspicious-orig.bro
|
text/plain
|
root:root
|
0o644
|
1.4 KB
|
/usr/share/bro/policy/protocols/smtp/entities-excerpt.bro
|
text/plain
|
root:root
|
0o644
|
872 bytes
|
/usr/share/bro/policy/protocols/smtp/software.bro
|
text/plain
|
root:root
|
0o644
|
2.8 KB
|
/usr/share/bro/policy/protocols/ssh/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/ssh/detect-bruteforcing.bro
|
text/plain
|
root:root
|
0o644
|
3.1 KB
|
/usr/share/bro/policy/protocols/ssh/geo-data.bro
|
text/plain
|
root:root
|
0o644
|
1.5 KB
|
/usr/share/bro/policy/protocols/ssh/interesting-hostnames.bro
|
text/plain
|
root:root
|
0o644
|
1.5 KB
|
/usr/share/bro/policy/protocols/ssh/software.bro
|
text/plain
|
root:root
|
0o644
|
1008 bytes
|
/usr/share/bro/policy/protocols/ssl/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/protocols/ssl/expiring-certs.bro
|
text/plain
|
root:root
|
0o644
|
2.7 KB
|
/usr/share/bro/policy/protocols/ssl/extract-certs-pem.bro
|
text/plain
|
root:root
|
0o644
|
1.7 KB
|
/usr/share/bro/policy/protocols/ssl/heartbleed.bro
|
text/plain
|
root:root
|
0o644
|
9.1 KB
|
/usr/share/bro/policy/protocols/ssl/known-certs.bro
|
text/plain
|
root:root
|
0o644
|
2.4 KB
|
/usr/share/bro/policy/protocols/ssl/log-hostcerts-only.bro
|
text/plain
|
root:root
|
0o644
|
1.8 KB
|
/usr/share/bro/policy/protocols/ssl/notary.bro
|
text/plain
|
root:root
|
0o644
|
2.4 KB
|
/usr/share/bro/policy/protocols/ssl/validate-certs.bro
|
text/plain
|
root:root
|
0o644
|
5.5 KB
|
/usr/share/bro/policy/protocols/ssl/validate-ocsp.bro
|
text/plain
|
root:root
|
0o644
|
1.9 KB
|
/usr/share/bro/policy/protocols/ssl/weak-keys.bro
|
text/plain
|
root:root
|
0o644
|
5.0 KB
|
/usr/share/bro/policy/tuning/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/tuning/__load__.bro
|
text/plain
|
root:root
|
0o644
|
51 bytes
|
/usr/share/bro/policy/tuning/defaults/
|
|
root:root
|
0o755
|
|
/usr/share/bro/policy/tuning/defaults/__load__.bro
|
text/plain
|
root:root
|
0o644
|
76 bytes
|
/usr/share/bro/policy/tuning/defaults/extracted_file_limits.bro
|
text/plain
|
root:root
|
0o644
|
82 bytes
|
/usr/share/bro/policy/tuning/defaults/packet-fragments.bro
|
text/plain
|
root:root
|
0o644
|
583 bytes
|
/usr/share/bro/policy/tuning/defaults/warnings.bro
|
text/plain
|
root:root
|
0o644
|
386 bytes
|
/usr/share/bro/policy/tuning/json-logs.bro
|
text/plain
|
root:root
|
0o644
|
115 bytes
|
/usr/share/bro/policy/tuning/track-all-assets.bro
|
text/plain
|
root:root
|
0o644
|
313 bytes
|