This presentation investigates and reports on the potential synergy between CERT's "Yet Another Flowmeter" (YAF) (http://tools.netsa.cert.org/yaf/) suite of tools and the Bro network security monitor (www.bro.org) to perform enhanced collection and analysis of potential indicators of compromise. Specifically the presentation will detail the results of a project implementing an IPFIX mediator that collects meta-data enriched flow records from YAF and transforms them into Bro events. Using the Bro analysis framework this project then implemented scripts to track events and warn of suspicious activities. This presentation includes three parts: implementation of the mediator explanation of Bro analysis scripts and application to DNS and SSL monitoring. Attendees will learn considerations and requirements for the test project lessons learned during testing and how to assess potential benefits from combining YAF Bro or similar tools in their enterprises.