Key | Value |
---|---|
MD5 | 16E1813CA6F7F2FD66AB14282D9C1EE2 |
PackageArch | x86_64 |
PackageDescription | Prelude-Correlator allows conducting multi-stream correlations thanks to a powerful programming language for writing correlation rules. With any type of alert able to be correlated, event analysis becomes simpler, quicker and more incisive. This correlation alert then appears within the Prewikka interface and indicates the potential target information via the set of correlation rules. |
PackageMaintainer | Fedora Project |
PackageName | prelude-correlator |
PackageRelease | 4.el7 |
PackageVersion | 4.1.1 |
SHA-1 | 5A278D474982B737DCD199A0A619E9455A94D52B |
SHA-256 | 8E67D15A043FFF3B17BBA9CB9E88E4BD3338A120401B1E39B687FDD9949C7874 |
hashlookup:children-total | 34 |
hashlookup:trust | 50 |
The searched file hash includes 34 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/OpenSSHAuthPlugin.pyo |
FileSize | 2062 |
MD5 | 9F549D0C8E9324F0C49CA4CE08E24B9A |
SHA-1 | 0B54D58BC09D33745398D9D155223A41AB999C94 |
SHA-256 | 238EE8B827D2D3FD02783C8B601CA3C38598AE856BF5A3F427E297EBB71F15AC |
SSDEEP | 48:lYeammdmSic3LCFljazii/I1LwMJluZ1gmmUsilOOiK:ltmdmSic3LC3yi11LwM+1FmUsGOOiK |
TLSH | T1C84130D473E14C07D9A12378E87D16DE7E11E6F612415B6523B0A0BE2EC93E5C52D2A1 |
Key | Value |
---|---|
FileName | ./var/lib/prelude-correlator/prelude-correlator/spamhaus_drop.dat |
FileSize | 22086 |
MD5 | E460077A27327E1506741A6164A7491C |
SHA-1 | 12F3358C94A43C9C187CACB8A74F6C2A6A030495 |
SHA-256 | A4693337B797CDC104056FB98D6D53582DC2975D8C88DF0D50D588340FD3F573 |
SSDEEP | 384:mRZrfiNHZYy/cyjjtSHEpCw08rvOx/ac8GWf+1IW9P5ReSZNNesl29ZqpzZ9skGr:mibYHicZzmE0 |
TLSH | T1E1A249F2AFF519FFCCD0609BD22FC539A123A6C175E5B7125F4F2250B92A880762B518 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventScanPlugin.pyo |
FileSize | 1394 |
MD5 | A623CEFDB6792DECD277E126565498A7 |
SHA-1 | 19BEB31172BAAFD65191EE9F2A6DCCBDD79B9EF9 |
SHA-256 | 6E045EA56C4B4568EF3179DA497D14EC28680C203017F02F85A10C6E415FDD55 |
SSDEEP | 24:lPIalq+Oj9DySzCzoxjWOejC06eL2oHHsFjRmu5FxJ0Ms1Me0MpFu:lP0jLAo7cLpsFjRmtZcR |
TLSH | T18921FED093E88847E9F91634E565029B7E20F5F316109B28236C549E3ED97B2CD6E3C9 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/BruteForcePlugin.pyo |
FileSize | 2795 |
MD5 | 2E57EBF2125391672596E7B314160509 |
SHA-1 | 1A72CCFF2EBEA7D803E581D816117EB7774BA65D |
SHA-256 | 5BB3676F7336308702BC48612C03F1085D379BDC3EA2ECD43D3E33D8101DA6D8 |
SSDEEP | 48:lIQAKqjW5+EVXqD8XPkOmwQOeQ98sB8HZY1R+QfMKcqQfQQPQVX:lpj1qD8Xcfxq8bkRroPIQYVX |
TLSH | T14751DED4A368890BE9B20370F4E5515FBE65F2FB06405B20227AA4797EC43B5C56E391 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/AUTHORS |
FileSize | 128 |
MD5 | 32AAD8CED8E624DBAE0EEF31DD5C5DA2 |
SHA-1 | 2DCA4EF98E77B78023183690BE189F207D0CBEB5 |
SHA-256 | 9F03F7E1D1DA2CC073BA5352210820D7FCF8E8BD72D849D0BA20003D958A51D9 |
SSDEEP | 3:L2bKgJEiMEuR9j9Vf0S4ie82ZsM+aENzpzeLKbvn:L2rQEe59J4r82aaeNLn |
TLSH | T1A5B02BCC166031372C0388083252C9E3014038E186FC8090B610D0C275330015400242 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/WormPlugin.py |
FileSize | 3068 |
MD5 | 055856F3D0DAD1CF6207F034D560BE6C |
SHA-1 | 326CA38CAEC873F12D1D7903DE469DE2302756E0 |
SHA-256 | 16B8E7601DC45643E090D4DBE737AA9CD0DCA169F57550FE5000D4414674AC41 |
SSDEEP | 48:tlDg4yUjHTY5xpt31ZQWXfjaXOF4Wgr4WKIc+/oZFOE0SVv8raOiULIV+:HEwT+xpt31ZQKhSJr7/N/Kv9O/Iw |
TLSH | T16751BA5D1220DBB6668302A6208F71E67319C6E342175C2C796DC28CAFB2DB141739F8 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventStormPlugin.py |
FileSize | 1768 |
MD5 | F7A20A2C5DC6B3B2BEB88A49B69EB604 |
SHA-1 | 340B29A7DF88B3105F736C3DA6C6E348BCC59B86 |
SHA-256 | 639BBF082925E9CE5C88F9B23D0FD2EE4EE759EC7F1B374A5ECFA562D1687125 |
SSDEEP | 24:QsJ4lHK2ahJiyUVOkHxHqTbVloY5w7qDvKEss+wiMXFFN4XFFoTDNsIQ0fGMNGM9:tWHDg4yUjHTYyuKnwVF6FoTpsIz/ |
TLSH | T17E31768D5471DA70590403F4214BA4DD73295AC366A9AC14B41CD98DFBD5EB582326EC |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventSweepPlugin.py |
FileSize | 2338 |
MD5 | 0DBB0169589FC3BB7744D526F00DE29E |
SHA-1 | 35956594B1399433C9DC5536DB20EA3AB1E178C2 |
SHA-256 | C1A945AC33A9676D0AF5CBFC73DA3A68BAF7B860AD2D6BAA7CA81A8CE0E115A3 |
SSDEEP | 48:tWHDg4yUjHTYy7VY1ZN8HFoTJcPBKsP1ZGU53:UHEwT/7MZGocPnPjGe3 |
TLSH | T1FE41C74E4520EDB0590502B4118BA1DD732959C3E52F5C1CBC2EC20EABE9E7686721EC |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/__init__.pyo |
FileSize | 135 |
MD5 | 2A523E05F06D5A5B06C4AB8C82C4E5CF |
SHA-1 | 35C3F352CB38B6C02594E61B8DC55647FAB0ADC4 |
SHA-256 | 85E6CA068951892D93516C1BC2D2EA9156A03AB1E413CD631FE5F664EF711940 |
SSDEEP | 3:9TGtOleh/Tj3tNltNltWPU0B7QMXQU2NKlQRzaiitn:dZeh/T4CMXQTNKWRaF |
TLSH | T13FC092D0A7314142E8B82674F640428EAA95A8A3012178217118048F1E8E0A98E2C2D7 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/FirewallPlugin.pyo |
FileSize | 3672 |
MD5 | 7DD1968D4640D0CBA7EB0D0DBBD33F7C |
SHA-1 | 382B351492D4C1089AB59AF61EA075C3900430EA |
SHA-256 | 1CC09467FE0BB018B7D94252B23C8AA697EAB59E5B1F2106D40479E1ED9D1175 |
SSDEEP | 96:l7sVzFpbq9uou8ML6rXS8nAlWexYZtLa8QPo+xf:Izm99zMsSBWYYZtLVAf |
TLSH | T1B671F0D0A3E0894FD6F82374E4B45657BD25F5F261426B1126F8E0BABCD43B1D92C2C1 |