From 05549a236205a97011241d26460c8a7d6f65e33b Mon Sep 17 00:00:00 2001 From: Wes Lambert Date: Mon, 2 Nov 2020 21:36:44 +0000 Subject: [PATCH] Add Zeek intel.dat --- salt/zeek/policy/intel/intel.dat | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 salt/zeek/policy/intel/intel.dat diff --git a/salt/zeek/policy/intel/intel.dat b/salt/zeek/policy/intel/intel.dat new file mode 100644 index 000000000..ca10994b6 --- /dev/null +++ b/salt/zeek/policy/intel/intel.dat @@ -0,0 +1,5 @@ +#fields indicator indicator_type meta.source meta.do_notice +# EXAMPLES: +#66.32.119.38 Intel::ADDR Test Address T +#www.honeynet.org Intel::DOMAIN Test Domain T +#4285358dd748ef74cb8161108e11cb73 Intel::FILE_HASH Test MD5 T