alphasoc / nfr

A lightweight tool to score network traffic and flag anomalies
https://alphasoc.com
Other
122 stars 19 forks source link

Bro dhcp.log support #73

Open chrisforce1 opened 5 years ago

chrisforce1 commented 5 years ago

This is important as it ties in with our strategy to pick up DHCP events and provide better alerting (in particular host MAC addresses, hostnames, and user details for sources, versus IP addresses that customers must then correlate), as per https://github.com/alphasoc/ops/issues/353 and https://github.com/alphasoc/nba/issues/107.