Slide 35
Slide 35 text
The Bro Intel Framework
#fields indicator indicator_type meta.source meta.url meta.do_notice meta.if_in
000007.ru Intel::DOMAIN MalwareDomains http://malwaredomains.com/files/justdomains F -
01100001 00100000 01110111 01101000 01101111 01101100 01100101
00100000 01100010 01110101 01101110 01100011 01101000 00100000
01101111 01100110 00100000 01100100 01100001 01110100 01100001
00100000 01101000 01100101 01110010 01100101 00100001 00100001
intel metadata controls
Intel::ADDR
Intel::URL
Intel::SOFTWARE
Intel::EMAIL
Intel::DOMAIN
Intel::USER_NAME
Intel::FILE_HASH
Intel::FILE_NAME
Intel::CERT_HASH
Intel Types
Intel.log
!