policy/protocols/smtp/detect-suspicious-orig.bro

SMTP
Namespace:SMTP
Imports:base/frameworks/notice/main.bro, base/protocols/smtp/main.bro
Source File:/scripts/policy/protocols/smtp/detect-suspicious-orig.bro

Summary

Runtime Options

SMTP::suspicious_origination_countries: set &redef Places where it’s suspicious for mail to originate from represented as all-capital, two character country codes (e.g., US).
SMTP::suspicious_origination_networks: set &redef  

Redefinitions

Notice::Type: enum  

Detailed Interface

Runtime Options

SMTP::suspicious_origination_countries
Type:set [string]
Attributes:&redef
Default:{}

Places where it’s suspicious for mail to originate from represented as all-capital, two character country codes (e.g., US). It requires Bro to be built with GeoIP support.

SMTP::suspicious_origination_networks
Type:set [subnet]
Attributes:&redef
Default:{}
Copyright 2016, The Bro Project. Last updated on January 10, 2019. Created using Sphinx 1.7.5.