A powerful, easily deployable network traffic analysis tool suite
Hedgehog Linux’s management of intel files is identical to what is done by a Malcolm instance’s Zeek containers. Please see Zeek Intelligence Framework in the main Malcolm documentation for more information. For Hedgehog Linux, the only deviations from what is outlined in that document are that some of the file locations are different than they are on a Malcolm instance:
ZEEK_INTEL_REFRESH_CRON_EXPRESSION
environment variable can be found in /opt/sensor/sensor_ctl/control_vars.conf
./zeek/intel
directory is /opt/sensor/sensor_ctl/zeek/intel
ZEEK_INTEL_REFRESH_CRON_EXPRESSION
, run /opt/zeek/bin/zeek_intel_setup.sh true