Skip to content

Decoding for File Hash Events and additional Packet Encoding Options

Compare
Choose a tag to compare
@skhademcis skhademcis released this 16 Dec 20:45
· 41 commits to master since this release
9aafcd3

Removed byte hex encoding for file hash fields, malware event fields (records 125,502 and 511) no longer contain the b'<file_hash>' wrapper encoding.

Added additional configuration options for packet records, you can now select whether or not to include the original packet in the record which contains the payload and the packet header, this configured using the following variable in the estreamer.conf

includeOriginalPacket: true in (https://github.com/CiscoSecurity/fp-05-firepower-cli/blob/master/default.conf#L56) estreamer.conf