detect_suspicious
Detect suspicious activity in PCAP files using predefined rules to support network forensics and threat hunting.
Instructions
Detect suspicious activity in the loaded PCAP based on predefined rules.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ruleset | No | Ruleset to use for detection | default |
| session_id | Yes | ID of the session |