Key | Value |
---|---|
MD5 | B7FD6019EF4D20C9A5E087CA2D859D32 |
PackageArch | noarch |
PackageDescription | Prelude-Correlator allows conducting multi-stream correlations thanks to a powerful programming language for writing correlation rules. With any type of alert able to be correlated, event analysis becomes simpler, quicker and more incisive. This correlation alert then appears within the Prewikka interface and indicates the potential target information via the set of correlation rules. |
PackageMaintainer | daviddavid <daviddavid> |
PackageName | prelude-correlator |
PackageRelease | 1.mga7 |
PackageVersion | 5.0.1 |
SHA-1 | A37CEFBB43B18568EE13D14C8B9109DDBDABD455 |
SHA-256 | 749934170293619538760899808A6F5549C573B7F9D71582F313366D704A2AC5 |
hashlookup:children-total | 69 |
hashlookup:trust | 50 |
The searched file hash includes 69 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventSweepPlugin.py |
FileSize | 2391 |
MD5 | 884CD59F9DED868D718A187960FDB848 |
SHA-1 | 021B6FE96FECDE4B382D317546872B0E7E007794 |
SHA-256 | 7DC282FA106F067DF40008B96A4A578918AB1CA0283D1BF9018E7F326A454441 |
SSDEEP | 48:tI+HDg4yUjHTYyZVY1ZN8HFoTJc7ICsPlZGUA3:a+HEwT/ZMZGoc7ItPTGp3 |
TLSH | T1FA41C94E4520DDB0690506B4118BA0DC332919C3A52F6C18BD2EC34EAFE9E7786724EC |
Key | Value |
---|---|
FileName | ./usr/lib/python2.7/site-packages/preludecorrelator/main.pyo |
FileSize | 11788 |
MD5 | AC5A630990BA2368DE98B80A25B1E9A6 |
SHA-1 | 093B11626F91E1849E56290F213A51FE9A594A56 |
SHA-256 | 6261BD7A9752500033D2765F4466BE4A95668B1E59F3BA5AF002BEC1A38A1495 |
SSDEEP | 192:ryVL8hkof0vhZIvmKTFC9dY+Ff804Kmh2JHMIo7HNO223+3Z5ZsMbSzBade:ryN3o0vamKw05TpAJDosfczZsCSzBX |
TLSH | T132322EC0B3B9096BE5602675F1F01207DE75F0B72E513B9132A8B4BA3DC9299C92E7C5 |
Key | Value |
---|---|
FileName | ./usr/lib/python2.7/site-packages/preludecorrelator/context.pyo |
FileSize | 14279 |
MD5 | A4FD38A100E6D44022C853825CB2AA1A |
SHA-1 | 0C83C293F40ECB8E1E2CCFED8B70B287EF3F40B6 |
SHA-256 | DC66521BA407B23549285AD788AE42B69C62FD2ABA496A0EF893D462B944FBC2 |
SSDEEP | 192:bqxzWu/Bom6oGDIB1AKGSClyIrfy5wbfkLz42kbik+wGfzT5C1Hv4uapyO6fJeFy:ApomjqKAyIUifkLz4tikKbTQ2us6fsy |
TLSH | T17E5201D0B3B9495BEA615670F1F012479A76F0775602BB5232ACB4B93CD83A8C86F3D1 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/SpamhausDropPlugin.pyo |
FileSize | 4342 |
MD5 | 87384E9C6BB742C394F53CD48FD0015B |
SHA-1 | 1416107FFA8D5F51520D946E9A901078FE2BBD5D |
SHA-256 | 93A962B113A4442620D14957A1621936E713B32F2F73D7BF9E426433AB158174 |
SSDEEP | 96:8n/sPhabvbwEiN5J4FZJWdjpJnbbX08nINl2yNBUKrVMpSE1g:WsPcbON5WfsFglzfc1g |
TLSH | T13491F0D0A3F0484BE8B52374E5F9514BBE65F1F36240971621ACA0BA7ECA7B6C91C3D1 |
Key | Value |
---|---|
FileName | ./usr/lib/systemd/system/prelude-correlator.service |
FileSize | 321 |
MD5 | CB1C2E965A028FA4D45B0312A68DF4B1 |
SHA-1 | 1A011BC0634DA1C9587970CE1356AC0D0B59012E |
SHA-256 | 641BF3A097CC9A11C2E1196063519D55A2EAA550A414A9E01BDEC7B981B89A9C |
SSDEEP | 6:z8L49JVKqolXN5aXjyADMzdK+aBNUZVQDMVQDsPWfGB/QDMVQDsBILQmWA4Rv:z6EJIlXNwTTDOK+aBNUrcUQDDfDUQDsx |
TLSH | T18EE086E5B6307870EC1537A8ED2784C40D4631CD462EE1A037A120E8B8934C6C2112F3 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventSweepPlugin.pyo |
FileSize | 1623 |
MD5 | 830129363BA7AF2DA6CDEBFE22843699 |
SHA-1 | 220584610B488F64509C5F7767F5E3C2233815D7 |
SHA-256 | 32C44C817194B276106D04FD98E76D8A8CD599D043269FCFC64AED01437001E6 |
SSDEEP | 24:PIalq+m9vFtZezB1qjC06QLYe7ksPuJVCAL9sSuFFMthikQMNNblyQM00QMeFp:P0vdoeLYAksPQVHLyChikQ6/yQsQp |
TLSH | T1213133E053F08816E5B61634F5B802AB7E21F4F752514B263779D89A3EC57B1C91C1CD |
Key | Value |
---|---|
FileName | ./usr/lib/python2.7/site-packages/preludecorrelator/plugins/__init__.pyo |
FileSize | 244 |
MD5 | 0BC818D733C55D7B355AA59138B758EB |
SHA-1 | 22BE54D77DFBCFD789F93A6C1A11ED5A4417A61F |
SHA-256 | 4E63FEB1839F5A0E84B4977A25F6DEE3DB3B117E686783B0B30D312C27F1FFE6 |
SSDEEP | 6:juW5/hIq/hH0TcknIaUgh+Xe29Y3xmDrnQMVZncRaF:DhhIq2TDIax+Xe2fdZncgF |
TLSH | T185D0A7A2B67CC5E7E53E9530B000119B4A98A47761116282B2A075791A89590023594E |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/OpenSSHAuthPlugin.pyo |
FileSize | 2095 |
MD5 | 903809A8F9E834A87E2E0A5F72717738 |
SHA-1 | 28D59B3C0357224D63696CD63F33349D24F9F41A |
SHA-256 | 169E10F58DFA0AF05B21D9522C2AC4F44D72349EA9DF7CF8AA612F9A521567B1 |
SSDEEP | 48:YeammdmSic3LCFljazP90sXyzYJluZ1UFmUDlbc8BiK:tmdmSic3LC3yVjyzY+1UFmU5bc8BiK |
TLSH | T1C94140C473E14C07D9A12378E87916DEBE11E6F612419B6523B4A0BE2ED93B5C52C2A1 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/AUTHORS |
FileSize | 128 |
MD5 | 32AAD8CED8E624DBAE0EEF31DD5C5DA2 |
SHA-1 | 2DCA4EF98E77B78023183690BE189F207D0CBEB5 |
SHA-256 | 9F03F7E1D1DA2CC073BA5352210820D7FCF8E8BD72D849D0BA20003D958A51D9 |
SSDEEP | 3:L2bKgJEiMEuR9j9Vf0S4ie82ZsM+aENzpzeLKbvn:L2rQEe59J4r82aaeNLn |
TLSH | T1A5B02BCC166031372C0388083252C9E3014038E186FC8090B610D0C275330015400242 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/BusinessHourPlugin.py |
FileSize | 1619 |
MD5 | EA797CBE632FF964FDA3F81682872771 |
SHA-1 | 349470B70447BCD34F1B5E508D06143F35747EAE |
SHA-256 | 92D6A1822E6991D85920E41F2F24A55650ACF584078905217BC9518E206ABA28 |
SSDEEP | 24:QYycgK2ahJiyUVOkHxHqTbVloY5AwHF4kqTPs+wcGSHyAH7pCyZE1aryk:HypDg4yUjHTYh45TP4SSAbpCaj |
TLSH | T12331368E91769DB16A5103D5344F55DE732A1A97929B98D4395C818CBF04EF203B33E4 |