Actions
Feature #7103
openssh: extra fields and keywords
Description
Consider adding more ssh protocol fields (to the existing ssh protocol logging) and ssh keywords (to the rules for matching) to be able to match on such cases as described in the blog here:
https://corelight.com/blog/newsroom/news/zeek-metadata-ssh-terrapin
- Message authentication
- Encryption
- Key Exchange
- Compression
This is good both for detection and audit of networks traffic
Actions