# File extraction package

**URL:** <https://community.zeek.org/t/file-extraction-package/6104>\
**Category:** Zeek\
**Created:** [April 27, 2020, 9:08pm UTC](https://community.zeek.org/t/file-extraction-package/6104 "2020-04-27T21:08:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kayode\_Enwerem](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@Kayode\_Enwerem](https://community.zeek.org/u/Kayode_Enwerem)\
**Post date:** [April 27, 2020, 9:08pm UTC](https://community.zeek.org/t/file-extraction-package/6104/1 "2020-04-27T21:08:08Z")

</div>

Hello,

We are trying to do some customization to the file extraction package [https://github.com/hosom/file-extraction](https://github.com/hosom/file-extraction)

Does any one have any suggestions on how I can get any of these done?

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [April 29, 2020, 5:02pm UTC](https://community.zeek.org/t/file-extraction-package/6104/2 "2020-04-29T17:02:53Z")

</div>

> Hello,
> 
> We are trying to do some customization to the file extraction package [GitHub - hosom/file-extraction: Extract files from network traffic with Zeek.](https://github.com/hosom/file-extraction)
> 
> Does any one have any suggestions on how I can get any of these done?
> 
> Is there a way to define what network you want the “file extracting package” to extract the files from? Instead of extracting files from all the networks defined in network.cfg. Example: if I have 7 subnets defined in network.cfg but I only the file extracting package to extract files from 2 out of the 7.

yes, just make a set[subnet] and add the networks you want to it. the  
networks.cfg just auto generates one for you called Site::local\_nets

> Is there a way to dedup the extracted files. Example: If a file was sent to 20 people, I only want to see the file 1 time instead of 20 times.

easiest way to do this part is to just name the file the hash, but you  
could track recent files with a set[string].

> We would also like to exclude certain file types based coming via SMB. Example: excluding all .pdf files I just want to exclude .pdf files coming via SMB.

If you look at how the plugins in that package are written, they are  
just small scripts containing an if statement:

> <https://github.com/hosom/file-extraction/blob/master/scripts/plugins/extract-pdf.zeek>

so you would just need something like

const pdf\_types: set[string] = { "application/pdf" };

hook FileExtraction::extract(f: fa\_file, meta: fa\_metadata) &priority=5  
{  
&nbsp;&nbsp;&nbsp;&nbsp;if ( f$source != "SMB" && meta$mime\_type in pdf\_types )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;break;  
}

or keep extracting all pdfs and ignore the ones that come from smb.

hook FileExtraction::ignore(f: fa\_file, meta: fa\_metadata)  
{  
&nbsp;&nbsp;&nbsp;&nbsp;if ( f$source == "SMB" && meta$mime\_type in pdf\_types )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;break;  
}

---

<div class="post-metadata">

**Author:** ![Kayode\_Enwerem](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@Kayode\_Enwerem](https://community.zeek.org/u/Kayode_Enwerem)\
**Post date:** [April 29, 2020, 7:59pm UTC](https://community.zeek.org/t/file-extraction-package/6104/3 "2020-04-29T19:59:34Z")

</div>

Thanks for the response Justin. How do I make a "set[subnet]" and what file do I add it in?

---

<div class="post-metadata">

**Author:** ![Kayode\_Enwerem](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@Kayode\_Enwerem](https://community.zeek.org/u/Kayode_Enwerem)\
**Post date:** [April 30, 2020, 8:54pm UTC](https://community.zeek.org/t/file-extraction-package/6104/4 "2020-04-30T20:54:38Z")

</div>

Also is there a way to have Zeek organize my extracted files on an hourly basis. So I want zeek to store all extracted files from each hour in a separate timestamped folder.

I currently have the extracted files being stored in this directory: /logs/bro/spool/extracted\_files/

Which I created and defined in:  
/usr/local/zeek/share/zeek/site/file-extraction/ config.zeek

redef path = "/logs/bro/spool/extracted\_files/";

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:47pm UTC](https://community.zeek.org/t/file-extraction-package/6104/5 "2022-05-06T15:47:14Z")

</div>


