lua:examples
Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
lua:examples [2018/12/22 18:11] – created veera | lua:examples [2018/12/22 18:29] (current) – [QUIC analyzer] veera | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | |||
====== Script examples ====== | ====== Script examples ====== | ||
Explains various programming techniques with real examples. | Explains various programming techniques with real examples. | ||
- | ==== UA-Parser | + | ===== Where to find more Trisul scripts ===== |
+ | The following locations contain working Trisul LUA scripts | ||
+ | |||
+ | - [[https:// | ||
+ | - [[https:// | ||
+ | - [[https:// | ||
+ | |||
+ | |||
+ | ===== UA-Parser ===== | ||
+ | |||
+ | Demonstrates how to scan Intel artifacts against hundreds of regexes using Google RE2 | ||
[[lua: | [[lua: | ||
- | ==== QUIC analyzer ==== | + | ===== QUIC analyzer |
A G-QUIC (Google QUIC) analyzer that parses a UDP-443 protocol, extracts indicators, and certificates. Learn how to use LuaJIT FFI to work with decompression, | A G-QUIC (Google QUIC) analyzer that parses a UDP-443 protocol, extracts indicators, and certificates. Learn how to use LuaJIT FFI to work with decompression, | ||
[[lua: | [[lua: | ||
+ | |||
+ | ===== Strelka | ||
+ | |||
+ | Strelka is a file scanning framework. This little script integrates Trisul File Extraction with Strelka scanning. The scan results in the form of JSON is fed back into Trisul as resources for search, alerting, or analysis. | ||
+ | |||
+ | [[lua: | ||
lua/examples.1545482494.txt.gz · Last modified: 2018/12/22 18:11 by veera