Moloch和Zeek 网络流量分析支持协议

Supported Protocols

Malcolm uses Zeek and Moloch to analyze network traffic. These tools provide varying degrees of visibility into traffic transmitted over the following network protocols:

TrafficWikiOrganization/SpecificationMolochZeek
Internet layer🔗🔗
Border Gateway Protocol (BGP)🔗🔗 
Building Automation and Control (BACnet)🔗🔗 
Distributed Computing Environment / Remote Procedure Calls (DCE/RPC)🔗🔗 
Dynamic Host Configuration Protocol (DHCP)🔗🔗
Distributed Network Protocol 3 (DNP3)🔗🔗 
Domain Name System (DNS)🔗🔗
EtherNet/IP / Common Industrial Protocol (CIP)🔗 🔗🔗 
FTP (File Transfer Protocol)🔗🔗 
Google Quick UDP Internet Connections (gQUIC)🔗🔗
Hypertext Transfer Protocol (HTTP)🔗🔗
Internet Relay Chat (IRC)🔗🔗
Kerberos🔗🔗
Lightweight Directory Access Protocol (LDAP)🔗🔗
Modbus🔗🔗 
MQ Telemetry Transport (MQTT)🔗🔗 
MySQL🔗🔗
NT Lan Manager (NTLM)🔗🔗 
Network Time Protocol (NTP)🔗🔗 
Oracle🔗🔗 
PostgreSQL🔗🔗 
Process Field Net (PROFINET)🔗🔗 
Remote Authentication Dial-In User Service (RADIUS)🔗🔗
Remote Desktop Protocol (RDP)🔗🔗 
Remote Framebuffer (RFB)🔗🔗 
S7comm / Connection Oriented Transport Protocol (COTP)🔗 🔗🔗 🔗 
Session Initiation Protocol (SIP)🔗🔗 
Server Message Block (SMB) / Common Internet File System (CIFS)🔗🔗
Simple Mail Transfer Protocol🔗🔗
Simple Network Management Protocol🔗🔗
SOCKS🔗🔗
Secure Shell (SSH)🔗🔗
Secure Sockets Layer (SSL) / Transport Layer Security (TLS)🔗🔗
Syslog🔗🔗
Tabular Data Stream🔗🔗 🔗
Telnet / remote shell (rsh) / remote login (rlogin)🔗🔗🔗🔗
WireGuard🔗🔗🔗 
various tunnel protocols (e.g., GTP, GRE, Teredo, AYIYA, IP-in-IP, etc.)🔗 
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值