Key | Value |
---|---|
MD5 | 3D87F6A51FC6A39DB06F47DEA7233C5E |
PackageArch | ppc64le |
PackageDescription | Prelude-Correlator allows conducting multi-stream correlations thanks to a powerful programming language for writing correlation rules. With any type of alert able to be correlated, event analysis becomes simpler, quicker and more incisive. This correlation alert then appears within the Prewikka interface and indicates the potential target information via the set of correlation rules. |
PackageMaintainer | Fedora Project |
PackageName | prelude-correlator |
PackageRelease | 1.el7 |
PackageVersion | 5.2.0 |
SHA-1 | 283E36D1BE284294349EAC74944D308E7584AE02 |
SHA-256 | 095517188A9685621AEBED68EAF641FFE2C5F6715D25800D78262BBC0A7180BC |
hashlookup:children-total | 34 |
hashlookup:trust | 50 |
The searched file hash includes 34 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./var/lib/prelude-correlator/prelude-correlator/ciarmy.dat |
FileSize | 215845 |
MD5 | 4D74A48FCAF9BE65572B7865A7914C52 |
SHA-1 | 027D69A6CBF1A522A6F39F891AAA5FF3C252D556 |
SHA-256 | A8F69235B1B442A1515DD6E44B5CA0D299B3CE25F1EE6596D88015BC987CFD40 |
SSDEEP | 3072:Wn+qhnASubteC9PmpdYQP22ybNY40LIbZxSqy+lZX2YGPrbqy+1IwN2:Wn+KnTC9lMwN2 |
TLSH | T1E824885573BF2FF5CEC6808E5382C4A6609A51A7DAA3F5E49FDB36807D01080FAF4652 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/BusinessHourPlugin.py |
FileSize | 1782 |
MD5 | B9456CC17B7D83D5E4984E4439EF42BD |
SHA-1 | 05A8AA84DAC3B52538900E92145E40289595E223 |
SHA-256 | 35D495CACCEBD01F14BC4802C385B6E248DF80C027919676CEDBAD171CE53D22 |
SSDEEP | 24:efbmIjvUpbkgK2ahJiyUVOkHxHqTbVloY5AwHF4kqTPs+wcGSHyAH7pCyZE1aryk:efyIjvU9xDg4yUjHTYh45TP4SSAbpCaj |
TLSH | T15C31438E91719DB16A1103E5348F55DEB22A1A97D29A98983D5C818C7F04EF202B73E4 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/NEWS |
FileSize | 17991 |
MD5 | 54B012B09947277031B17573041F98DC |
SHA-1 | 1AC708B9825A5BC046D3C4A53A1933E361DFE4C7 |
SHA-256 | CF6F7B31ED5AD5E133C3B5E24EFBF9AB581DD7541BD8036B7CF3D6718C3A94C9 |
SSDEEP | 384:OKAQJMpN4mtKUdLA+pR+Y9DQFBKmWOgyrx:I+wHvWmOgw |
TLSH | T1C78287E277343712799227A6D2CB41DAB718A1EB9233D0747B9895C87A03063D3776CB |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventScanPlugin.py |
FileSize | 2191 |
MD5 | 47B28463DDB94268C26E550C37C7EA8D |
SHA-1 | 1CD68BD9325E29448D88FF96FD8A351CFB8BB61E |
SHA-256 | 1E9720EE73766F85F460974AED30D9D297C82DA289F585F3D3D7FBAC0FB34253 |
SSDEEP | 48:efyIjvRW4FDg4yUjHTYyFIZN8rF2TtWSCsFEP:efyaVEwT/qZuuWStF0 |
TLSH | T16141B84E9320DAB05D0906B5104791DC732916C3962E5C08BD2CD38D7BA5EB681755FC |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/WormPlugin.pyo |
FileSize | 2147 |
MD5 | 8FC0662DDD70F5BB17E96EE80B1FFE79 |
SHA-1 | 2DDEC4C7E4F1E6FF7238732383977A315803C034 |
SHA-256 | BBDFF37E0D5AF7A74D96F73C3E2BEAA33A3BCDDD7E3ED7E61F8292F78ED150A7 |
SSDEEP | 48:T6DI8nktojbDZfOgqYml3g6qJp8izLIv30xFqH3ZUeJvNb:yI8nactDmvE8WI/0z4ZJNb |
TLSH | T1604145D0A3A04C0BD8A51334F4B963CBBE61F2FA0141672633ACA4A93DF83B4D51D386 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventStormPlugin.pyo |
FileSize | 1279 |
MD5 | 6DC3FBDDFD4A0257C65957FF4001B6D7 |
SHA-1 | 32E4B12283D3A27AC4511AC7A0E5F78CCCCD3E26 |
SHA-256 | 848904B483078E45AAA2389FFF59386F9A57BE88936A8A095FA9E897AE221B10 |
SSDEEP | 24:TIalq+1T9h/8ia3CclU8oej2MePSkYegAUuFJ0QMmTrLQMmr0QMmK+Jp:T0Av9a3CK3jT6vYeFUZQ/QMQt |
TLSH | T13321E0D093E48C0AE9B90334F59A019BBF15B9F72A408F25365814AD3EC9771CA2C3DA |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/AUTHORS |
FileSize | 125 |
MD5 | CD2BB2FA7D21CFA818A39915F219C78D |
SHA-1 | 36BEADC5993E89C3CB13B50245BA1420B2699517 |
SHA-256 | 6597296AA1A8E5A55E8B9C3116BD9AD93A7C435D54E0B17B38D776C8E906EE16 |
SSDEEP | 3:L2bKgJEiMEuR9D9Vf0S4FQXMk1aENzpzeLKbvn:L2rQEe9T4+Mk1aeNLn |
TLSH | T11EB02BCC151000073C438C446251C5D644C23CE0C5FC80406210F05136380005514293 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/DshieldPlugin.pyo |
FileSize | 3491 |
MD5 | A231997F5B2179BB2130937CF0A1FF27 |
SHA-1 | 37A618E4DEB7C96454A635C0BF0C6FC35E61C58F |
SHA-256 | 20D734FE2AA79EAEBC497D5E61A242BF786BB2EB7D8E935F5BAC8B090B7BA655 |
SSDEEP | 96:mdNzII4iFqXzajBjXEmRCl8nG5W64H0X8FgyWF:oNzJBkX6g340Xd |
TLSH | T115712FC1A3E08847E8B41275E9F89187BE65F2F75200971122BCA4BA3DD93A7D51D386 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/CIArmyPlugin.pyo |
FileSize | 3231 |
MD5 | EE6136240BBAE0B7EE491AD31D164DF8 |
SHA-1 | 412AC94C5A8308BDB2F81221ADD6306BDC621B72 |
SHA-256 | A1B687239CE2B9D6B78D2CCE8510C675AA4521389F5B7B5F9715AD53DF286201 |
SSDEEP | 96:mAN8j84i6CK7OjJHr7Vi8nK/VjE8FUbdzRP:7N8gBtK7m4RCN |
TLSH | T18D61B9C0E7E44C47E8B413B8E8F9518BBD66F2F35204931125ACA4BA3DDA2E5D91E3C1 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/SpamhausDropPlugin.py |
FileSize | 4217 |
MD5 | 3514F0C244B66448FCD5B437B34C34EC |
SHA-1 | 49DE807A426CB87FB65AF518E4A099541BC093DA |
SHA-256 | C2D8E7050A5EB3610BC31F9DEDA4C1719925990413507DE4423033AC55784DD0 |
SSDEEP | 48:efyIjfgODg4yUjHTYuHMjRM6mdohTFH93U7uv5QWt75Ojo75x5uzXBitHg:efyyDEwT5Mj+8hTFH67uhQNs74QtHg |
TLSH | T14A91D5AF2535D462AA17019050EBD1D1732AABC7844D90ADB4FCE288BF95C70D2B18EA |