[Bro] Question: How to block a malicious file

Giorgio Apuzzo giorgio.apuzzo at gmail.com
Mon Jun 6 08:29:48 PDT 2016


Hi,
I’m trying to write a script that after checking on virus total the hash of a file will block it if malicious.
I run a ruby script that checks the hash against virus total and return 0 if not malicious and more if not.
I have looked into the documentation but I can’t figure out how to block a file once I know it’s malicious..

Do I need an external tool?

Thanks

Giorgio Apuzzo
giorgio.apuzzo at gmail.com



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20160606/66a81e58/attachment.html 


More information about the Bro mailing list