Bro package for logging snippets of files without discovered mime types
Clone or download
Latest commit 248c030 Jul 15, 2017
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
scripts Package and license updates. Jul 15, 2017
LICENSE Package and license updates. Jul 15, 2017
README.rst Small readme updates. Jul 15, 2017
bro-pkg.meta Package and license updates. Jul 15, 2017

README.rst

Unknown MIME Type Discovery

This package is for Bro to help network analysts improve Bro by using their network to discover unknown file types. It does this by creating a log named unknown_mime_type_discovery.log that will log a configurable amount of data from the beginning of any files not found to already have a file type detection signature in Bro.

Installation

bro-pkg refresh
bro-pkg install sethhall/unknown-mime-type-discovery

Configuration

If you would like to log a different amount of the beginning of files with unknown mime types you can use the following configuration option in local.bro or another script you are loading. The default is to log 1000 bytes.

redef UnknownMimeTypeDiscovery::max_content_extraction = 250;