Document Kerberos 5 parsing events

pull/3391/head
Pierre Chifflier 7 years ago
parent 1076c7cd47
commit c51ff32adb

@ -83,3 +83,31 @@ Syntax::
Signature example::
alert krb5 any any -> any any (msg:"Kerberos 5 error C_PRINCIPAL_UNKNOWN"; krb5_err_code:6; sid:6; rev:1;)
krb5.weak_encryption (event)
----------------------------
Event raised if the encryption parameters selected by the server are weak or
deprecated. For example, using a key size smaller than 128, or using deprecated
ciphers like DES.
Syntax::
app-layer-event:krb5.weak_encryption
Signature example::
alert krb5 any any -> any any (msg:"SURICATA Kerberos 5 weak encryption parameters"; flow:to_client; app-layer-event:krb5.weak_encryption; classtype:protocol-command-decode; sid:2226001; rev:1;)
krb5.malformed_data (event)
---------------------------
Event raised in case of a protocol decoding error.
Syntax::
app-layer-event:krb5.malformed_data
Signature example::
alert krb5 any any -> any any (msg:"SURICATA Kerberos 5 malformed request data"; flow:to_server; app-layer-event:krb5.malformed_data; classtype:protocol-command-decode; sid:2226000; rev:1;)

Loading…
Cancel
Save