For the 1Q, you can easily define variables for ip addresses in zeek using the type “addr”. However, I don’t think you can do it in a signature file.
For the 2Q, have a look at https://docs.zeek.org/en/stable/scripts/base/utils/exec.zeek.html#id-Exec::run
For the 3Q, I think they use it at CERN in Geneva too.
Inviato: martedì 19 novembre 2019 13:45