StratosphereLinuxIPS
StratosphereLinuxIPS copied to clipboard
Read quic.log zeek file, detections done on the server_name for http and tls should be detected in the server_name in quic
Hey @AlyaGomaa is this a new detection module? Also where can I find quic.log zeek file?
Hi @patel-lay. I just created a new branch with a quick.log file. It is being merged into develop soon too. You can use this for your work.
This is not a new detection module, but just needs an adaptation of the current modules to read the SNI from quick.log files, just as it is being read from ssl.log files.
@patel-lay sebastian's branch is merged to develop