SCILabsMX / yaraZeekAlertLinks

This script scans the files extracted by Zeek with YARA rules located on the rules folder on a Linux based Zeek sensor, if there is a match it sends email alerts to the email address specified in the mailTo parameter on yaraAlert.conf file. The alert includes network context of the file transfer and attaches the suspicious file if it is less tha…
62Updated last year

Alternatives and similar repositories for yaraZeekAlert

Users that are interested in yaraZeekAlert are comparing it to the libraries listed below

Sorting: