detect/file: add file.data, small cleanups

pull/3826/head
Victor Julien 6 years ago
parent b5d5389438
commit d64fbb71ae

@ -80,7 +80,8 @@ int PrefilterMpmFiledataRegister(DetectEngineCtx *de_ctx,
*/
void DetectFiledataRegister(void)
{
sigmatch_table[DETECT_FILE_DATA].name = "file_data";
sigmatch_table[DETECT_FILE_DATA].name = "file.data";
sigmatch_table[DETECT_FILE_DATA].alias = "file_data";
sigmatch_table[DETECT_FILE_DATA].desc = "make content keywords match on file data";
sigmatch_table[DETECT_FILE_DATA].url = DOC_URL DOC_VERSION "/rules/http-keywords.html#file-data";
sigmatch_table[DETECT_FILE_DATA].Setup = DetectFiledataSetup;

@ -71,6 +71,7 @@ void DetectFileextRegister(void)
sigmatch_table[DETECT_FILEEXT].Free = DetectFileextFree;
sigmatch_table[DETECT_FILEEXT].RegisterTests = DetectFileextRegisterTests;
sigmatch_table[DETECT_FILEEXT].flags = SIGMATCH_QUOTES_OPTIONAL|SIGMATCH_HANDLE_NEGATION;
sigmatch_table[DETECT_FILEEXT].alternative = DETECT_FILE_NAME;
g_file_match_list_id = DetectBufferTypeRegister("files");

@ -85,6 +85,7 @@ void DetectFilenameRegister(void)
sigmatch_table[DETECT_FILENAME].Free = DetectFilenameFree;
sigmatch_table[DETECT_FILENAME].RegisterTests = DetectFilenameRegisterTests;
sigmatch_table[DETECT_FILENAME].flags = SIGMATCH_QUOTES_OPTIONAL|SIGMATCH_HANDLE_NEGATION;
sigmatch_table[DETECT_FILENAME].alternative = DETECT_FILE_NAME;
sigmatch_table[DETECT_FILE_NAME].name = "file.name";
sigmatch_table[DETECT_FILE_NAME].desc = "sticky buffer to match on the file name";

Loading…
Cancel
Save