diff --git a/salt/zeek/files/local.zeek b/salt/zeek/files/local.zeek index 92104dbf0..843b39f2d 100644 --- a/salt/zeek/files/local.zeek +++ b/salt/zeek/files/local.zeek @@ -102,10 +102,10 @@ # @load policy/protocols/conn/mac-logging # JA3 - SSL Detection Goodness -@load policy/ja3 +@load ja3 # HASSH -@load policy/hassh +@load hassh # You can load your own intel into: # /opt/so/saltstack/bro/policy/intel/ on the master diff --git a/salt/zeek/init.sls b/salt/zeek/init.sls index e0f1f8c9b..471b6bcd1 100644 --- a/salt/zeek/init.sls +++ b/salt/zeek/init.sls @@ -110,6 +110,7 @@ so-zeek: - /opt/so/conf/zeek/node.cfg:/opt/zeek/etc/node.cfg:ro - /opt/so/conf/zeek/policy/securityonion:/opt/zeek/share/zeek/policy/securityonion:ro - /opt/so/conf/zeek/policy/custom:/opt/zeek/share/zeek/policy/custom:ro + - /opt/so/conf/zeek/policy/cve-2020-0601:/opt/zeek/share/zeek/policy/cve-2020-0601:ro - /opt/so/conf/zeek/policy/intel:/opt/zeek/share/zeek/policy/intel:rw - network_mode: host - watch: