Skip to content

Adds a Intel::WILDCARD_DOMAIN type to the Zeek Inteligence Framework

License

Notifications You must be signed in to change notification settings

jbaggs/wildcard-domain

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

wildcard-domain

In the default configuration, the Zeek Intelligence Framework requires exact matches for detection of intel items. This script adds a new Intel::WILDCARD_DOMAIN type that matches on the base domain name, regardless of what subdomain may be prepended to it. ( e.g.: "example.com" would match "example.com", "foo.example.com", "foo.bar.example.com", etc. )

Installation

zkg install jbaggs/wildcard-domain

About

Adds a Intel::WILDCARD_DOMAIN type to the Zeek Inteligence Framework

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages