diff --git a/format/README.md b/format/README.md index 2e86e92..94087f6 100644 --- a/format/README.md +++ b/format/README.md @@ -54,3 +54,6 @@ the next packet to be decoded as type 254 in the stream. The JSON object MUST at | ja3-jl | JA3 fingerprinting JL version | | d4-telemetry | D4 project sensor telemetry | | fascia | fascia JSON object | +| maltrail | [maltrail](https://github.com/stamparm/maltrail) logging | + +The D4 meta-type list is [available in JSON format](https://raw.githubusercontent.com/D4-project/architecture/master/format/meta-type.json). diff --git a/format/meta-type.json b/format/meta-type.json new file mode 100644 index 0000000..1c9f9ad --- /dev/null +++ b/format/meta-type.json @@ -0,0 +1,20 @@ +[ + { + "type": "ja3-jl", + "description": "JA3 fingerprint JL version", + "ref": "https://github.com/D4-project/sensor-d4-tls-fingerprinting" + }, + { + "type": "d4-telemetry", + "description": "D4 project sensor telemetry" + }, + { + "type": "fascia", + "description": "FASCIA JSON Object" + }, + { + "type": "maltrail", + "description": "Mailtrail logging", + "ref": "https://github.com/stamparm/maltrail" + } +]