Ambros, >> What should the extract-all-files.bro look like in order to >> only extract pdf, exe, doc and docx? The fa_metadata record contains the MIME type. Using the MIME type, you can make a condition on whether or not to extract the file. Mark