PUNCH-Cyber / stoq-plugins-public

stoQ Public Plugins
https://stoq.punchcyber.com
Apache License 2.0
72 stars 24 forks source link

Fix for tests, minor bugs, and async support for xorsearch #101

Closed mlaferrera closed 4 years ago

mlaferrera commented 4 years ago

I just tested the rule, and it's not hitting on many e-mails. I have a corpus of 4292 test e-mails from an operational network and it only identified 1969. Each of them are valid SMTP sessions.