Closed dougburks closed 4 years ago
sed -i 's|^#@load file-extraction|@load file-extraction|g' /opt/zeek/share/zeek/site/local.zeek
To test, please import a pcap that includes a Windows EXE download and then verify that the EXE was extracted to /nsm/zeek/extracted/.
/nsm/zeek/extracted/
Published: https://blog.securityonion.net/2020/03/elastic-687-now-available-for-security.html