# /zeek/hosom/file-extraction

**URL:** <https://community.zeek.org/t/zeek-hosom-file-extraction/7606>\
**Category:** Zeek\
**Tags:** development\
**Created:** [October 14, 2024, 9:20am UTC](https://community.zeek.org/t/zeek-hosom-file-extraction/7606 "2024-10-14T09:20:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![georgio](https://avatars.discourse-cdn.com/v4/letter/g/b5ac83/32.png) [@georgio](https://community.zeek.org/u/georgio)\
**Post date:** [October 14, 2024, 9:20am UTC](https://community.zeek.org/t/zeek-hosom-file-extraction/7606/1 "2024-10-14T09:20:43Z")

</div>

Hello!  
I am currently working on my first NDR solution and I choose zeek for this, I am wondering if this “zeek/hosom/file-extraction” module for file-extraction is considered safe since is not included on the official documentation. Thanks and have a nice one!

---

<div class="post-metadata">

**Author:** ![Richard\_Bejtlich](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/richard_bejtlich/32/597_2.png) [@Richard\_Bejtlich](https://community.zeek.org/u/Richard_Bejtlich)\
**Post date:** [October 15, 2024, 12:52pm UTC](https://community.zeek.org/t/zeek-hosom-file-extraction/7606/2 "2024-10-15T12:52:24Z")

</div>

> [@georgio](#):
>
> zeek/hosom/file-extraction

Some people do use it:

> [@Extract Specific File Types (Not All Files)](https://community.zeek.org/t/extract-specific-file-types-not-all-files/7027):
>
> Hello all, I am using version 5.0.7-0 Zeek-Lts. At the same time, multiple pcaps are processed in parallel. All files are extracted with the extension: …/policy/frameworks/files/extract-all-files.zeek How can I prevent the extraction of “Unknown” and “Archive” files that take a long time and slow down the processing of pcaps? I don’t want to extract such files in pcap. How can I get the remaining different types of files to be extracted when these types arrive and continue when they are no…
