beelives / bro-vuln-scan

A vulnerability scan detection script for Zeek (Bro)

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Zeek (Bro) Vulnerability Scan Detector

Build Status

A vulnerability scan detection script for Zeek (Bro). This script simply detects the difference between a basic scan and a vulnerability scan by whether a reasonable amount of data was transferred on a few ports or many hosts in a short period of time.

Many thanks to ncsa/bro-simple-scan on which this script is based.

Usage

$ bro-pkg install https://github.com/fkmclane/bro-vuln-scan.git

About

A vulnerability scan detection script for Zeek (Bro)

License:BSD 3-Clause "New" or "Revised" License


Languages

Language:Bro 100.0%