[Bro] spam mail message collector

Hyun Yoo easetheworld at gmail.com
Tue Aug 18 14:48:32 PDT 2015


Hello Bro. I am new to bro.
I think my task is more suitable to Bro than other NIDS.

There is a list of spammer email addresses and
I want to save the email subject and whole message of them.
(reassembled payload of tcp segments)
I tried a few events like log_smtp, tcp_contents but couldn't save the
whole stream.

Can anybody guide me to the right way, please?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20150819/b146e440/attachment.html 


More information about the Bro mailing list