Added Suspicious Entropy alert (#6563)

This commit is contained in:
MatteoBiscosi 2022-05-04 22:11:02 +02:00
parent 283ebda29c
commit 2bcf7c8dfa
11 changed files with 170 additions and 0 deletions

View file

@ -0,0 +1,31 @@
--
-- (C) 2019-22 - ntop.org
--
local checks = require("checks")
local flow_alert_keys = require "flow_alert_keys"
-- #################################################################
local script = {
-- Script category
category = checks.check_categories.security,
-- This script is only for alerts generation
alert_id = flow_alert_keys.flow_alert_ndpi_suspicious_entropy,
default_enabled = true,
default_value = {
},
gui = {
i18n_title = "flow_risk.ndpi_suspicious_entropy",
i18n_description = "flow_risk.ndpi_suspicious_entropy_descr",
}
}
-- #################################################################
return script