Key | Value |
---|---|
MD5 | 6FD6449E3CCDE14E26CDAA61BD1B1DF1 |
PackageArch | ppc64le |
PackageDescription | Prelude-Correlator allows conducting multi-stream correlations thanks to a powerful programming language for writing correlation rules. With any type of alert able to be correlated, event analysis becomes simpler, quicker and more incisive. This correlation alert then appears within the Prewikka interface and indicates the potential target information via the set of correlation rules. |
PackageMaintainer | Fedora Project |
PackageName | prelude-correlator |
PackageRelease | 1.el7 |
PackageVersion | 5.0.1 |
SHA-1 | D339D16D769D0849DC6C91578B4A86655AC824EC |
SHA-256 | 47E2DC4502C4F8AFEFCBDAC43FAF9B2237F2689A0C3610DAAB84B14895E531FE |
hashlookup:children-total | 34 |
hashlookup:trust | 50 |
The searched file hash includes 34 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventSweepPlugin.py |
FileSize | 2391 |
MD5 | 884CD59F9DED868D718A187960FDB848 |
SHA-1 | 021B6FE96FECDE4B382D317546872B0E7E007794 |
SHA-256 | 7DC282FA106F067DF40008B96A4A578918AB1CA0283D1BF9018E7F326A454441 |
SSDEEP | 48:tI+HDg4yUjHTYyZVY1ZN8HFoTJc7ICsPlZGUA3:a+HEwT/ZMZGoc7ItPTGp3 |
TLSH | T1FA41C94E4520DDB0690506B4118BA0DC332919C3A52F6C18BD2EC34EAFE9E7786724EC |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventScanPlugin.pyo |
FileSize | 1429 |
MD5 | D92619FCB1FDD694CFBC6709B904E4B3 |
SHA-1 | 22D83FBDC44A1089BE2F54CBF364ED2C4EAA423E |
SHA-256 | EE83E01AE0CA97C1A073D8A6DA6CAF0165992FA08251D876682B0A13B2960A68 |
SSDEEP | 24:PIalq+Oj9FCzCqVxj3HxvjC06eL2MeHHsFjsgAu5FxJ0MrWhznMc20MpFv:P0jmdPmcLTksFjsFtnBnQ |
TLSH | T1142111E0A3E88807E9B91634F5A5015B7E20F4F716145B28236C544E3ED97B2C85D3CD |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/OpenSSHAuthPlugin.pyo |
FileSize | 2095 |
MD5 | 903809A8F9E834A87E2E0A5F72717738 |
SHA-1 | 28D59B3C0357224D63696CD63F33349D24F9F41A |
SHA-256 | 169E10F58DFA0AF05B21D9522C2AC4F44D72349EA9DF7CF8AA612F9A521567B1 |
SSDEEP | 48:YeammdmSic3LCFljazP90sXyzYJluZ1UFmUDlbc8BiK:tmdmSic3LC3yVjyzY+1UFmU5bc8BiK |
TLSH | T1C94140C473E14C07D9A12378E87916DEBE11E6F612419B6523B4A0BE2ED93B5C52C2A1 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/AUTHORS |
FileSize | 128 |
MD5 | 32AAD8CED8E624DBAE0EEF31DD5C5DA2 |
SHA-1 | 2DCA4EF98E77B78023183690BE189F207D0CBEB5 |
SHA-256 | 9F03F7E1D1DA2CC073BA5352210820D7FCF8E8BD72D849D0BA20003D958A51D9 |
SSDEEP | 3:L2bKgJEiMEuR9j9Vf0S4ie82ZsM+aENzpzeLKbvn:L2rQEe59J4r82aaeNLn |
TLSH | T1A5B02BCC166031372C0388083252C9E3014038E186FC8090B610D0C275330015400242 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/BusinessHourPlugin.py |
FileSize | 1619 |
MD5 | EA797CBE632FF964FDA3F81682872771 |
SHA-1 | 349470B70447BCD34F1B5E508D06143F35747EAE |
SHA-256 | 92D6A1822E6991D85920E41F2F24A55650ACF584078905217BC9518E206ABA28 |
SSDEEP | 24:QYycgK2ahJiyUVOkHxHqTbVloY5AwHF4kqTPs+wcGSHyAH7pCyZE1aryk:HypDg4yUjHTYh45TP4SSAbpCaj |
TLSH | T12331368E91769DB16A5103D5344F55DE732A1A97929B98D4395C818CBF04EF203B33E4 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/WormPlugin.pyo |
FileSize | 2147 |
MD5 | 9574A463A009B886BCDCAF9AB3DEFDAE |
SHA-1 | 3C011124525034D91650E4B21D874EF43BE1D59F |
SHA-256 | 71DE5B740F2F66FC1101E761F0F9C937717C3CFD0FF3968237DFA089263BC8F7 |
SSDEEP | 48:P6DI8nktojbkfOgqYml3g6qJp8izLIv30xFqH3Z1eJvau:eI8nackDmvE8WI/0z4Zqau |
TLSH | T1844114D0A3A04C0BD8A51374F4B963CBBE61F1FA0141572633A8A4692DF83B4D51D386 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/CIArmyPlugin.pyo |
FileSize | 3232 |
MD5 | 96BE7A7E2DD364B1856C006248A625A4 |
SHA-1 | 3DEE0D097274AF973DA1CFC546938995BB711F2C |
SHA-256 | 12DC7097CBA5B061A42850C4293A76BFC7877042B34D8FBFE25065180FCBAD2B |
SSDEEP | 96:aAN8jY4i6WK7OjJHf7Ji8nK/5FE8FUbRzdvz:HN8EBZK7mARIh |
TLSH | T10F61AAC4E3E44847D8B413B8E8F4518BBD66F2F35604971125ACA4BA3DDE2A5D91E3C1 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventScanPlugin.py |
FileSize | 2014 |
MD5 | 803EEBAF4857B457795BF915104247FE |
SHA-1 | 419E580A956E82DECBEF2C50F747F845494048A8 |
SHA-256 | 773064E6F45505B21F38BB87056B6D59DB26A3CB926E5BD40A2ECC4B96C6A305 |
SSDEEP | 24:QsJ4Z+HK2ahJiyUVOkHxHqTbVloY5w7qas+wirAKC0s8ux4XFF2TtWCUoLQBsFLg:tI+HDg4yUjHTYyFIZN8rF2TtWSCsFEP |
TLSH | T1C241A94E9620DAF0680507A5214B95EC73294BC3556EAC08B91CC38DBFE5EB281725EC |
Key | Value |
---|---|
FileName | ./var/lib/prelude-correlator/prelude-correlator/spamhaus_drop.dat |
FileSize | 21514 |
MD5 | 821965522AFD25CFEF530C7D50BB5F72 |
SHA-1 | 440B0A5451C9FAF939E8B5D6FD51F7B69EACEB95 |
SHA-256 | 1856052263EC97DA5E9AEECD62D6670F509D3E1234B9D8B1D6E03946F540F14B |
SSDEEP | 384:wrfJ1Z7yHTZejw6xSjfGpgFY8rCKx9dvg9r80mLXIu3zqbXSBqqGQTn9o/vJ86zA:l68TT/EG7Z |
TLSH | T18EA259F2AEF519FF8CD0609BD22FC5397127A6C1B1E5F7165F4F2250782A4807A2B918 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/BruteForcePlugin.py |
FileSize | 3395 |
MD5 | 515CB388CBD3BB1E9F3E6C5BD559531B |
SHA-1 | 4B4C67C67CD7B4657D8542DAB780C5ACB57BF832 |
SHA-256 | DB3751B223CC65114BFDD76A1A221DEF1AC3CEE992FA293EB221F09170CC0588 |
SSDEEP | 48:tI+HDg4yUjHTYe6umhVFH7zEudVQVf78XGUetiQVANtjXSYAB8:a+HEwTp67/hEudq17Uetbkjic |
TLSH | T1FD61992F46385D51AB4203E1609BA0ED772E67D7469AAC2C783DD14CFF98DB242724EC |