file-extraction/scripts/plugins/store-files-by-sha1.zeek
Patrick Kelley e92000e5b0 Initial
2025-05-07 14:10:34 -04:00

24 lines
548 B
Plaintext

@load ../__load__
@load policy/frameworks/files/hash-all-files
event file_state_remove(f: fa_file)
{
if ( !f$info?$extracted || !f$info?$sha1 || FileExtraction::path == "" )
return;
local orig = f$info$extracted;
local split_orig = split_string(f$info$extracted, /\./);
local extension = split_orig[|split_orig|-1];
local dest = fmt("%s%s-%s.%s", FileExtraction::path, f$source, f$info$sha1, extension);
local cmd = fmt("mv %s %s", orig, dest);
when ( local result = Exec::run([$cmd=cmd]) )
{
}
f$info$extracted = dest;
}