From 2c259f223938a3f1cf37be1f9dc64495d826b99f Mon Sep 17 00:00:00 2001 From: Victor Julien Date: Thu, 29 Mar 2018 15:13:35 +0200 Subject: [PATCH] doc: add smb section to yaml --- doc/userguide/configuration/suricata-yaml.rst | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/doc/userguide/configuration/suricata-yaml.rst b/doc/userguide/configuration/suricata-yaml.rst index 4043deb6be..91a8b0f136 100644 --- a/doc/userguide/configuration/suricata-yaml.rst +++ b/doc/userguide/configuration/suricata-yaml.rst @@ -1447,6 +1447,29 @@ use of libhtp. # Accepted values - bestfit, status_400 and status_404. #set-path-unicode-mapping: bestfit +Configure SMB (Rust) +~~~~~~~~~~~~~~~~~~~~ + +.. note:: for full SMB support compile Suricata with Rust support + +The SMB parser will parse version 1, 2 and 3 of the SMB protocol over TCP. + +To enable the parser add the following to the ``app-layer`` section of the YAML. + +:: + + smb: + enabled: yes + detection-ports: + dp: 139, 445 + +The parser uses pattern based protocol detection and will fallback to ``probing parsers`` +if the pattern based detection fails. As usual, the pattern based detection is port +independent. The ``probing parsers`` will only run on the ``detection-ports``. + +SMB is commonly used to transfer the DCERPC protocol. This traffic is also handled by +this parser. + Engine output -------------