[Bro] Extract Executables

sec-x sec-x center.mnt at gmail.com
Sun Dec 25 02:56:46 PST 2016


Hi,

I recently used bro IDS - Default Policy (GetTraffic from TAP on the
network) and i want to analysis Files.
1-  extract all Executables Files from all traffic (http,smb and others
protocols).
2- md5 of all files that passed in the traffic.

How can i do it?


Thanks,

CM.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20161225/a547cab4/attachment.html 


More information about the Bro mailing list