diff --git a/doc/userguide/rules/index.rst b/doc/userguide/rules/index.rst index 2715da79ac..e174c6787b 100644 --- a/doc/userguide/rules/index.rst +++ b/doc/userguide/rules/index.rst @@ -34,6 +34,7 @@ Suricata Rules http2-keywords quic-keywords nfs-keywords + smtp-keywords app-layer xbits thresholding diff --git a/doc/userguide/rules/smtp-keywords.rst b/doc/userguide/rules/smtp-keywords.rst new file mode 100644 index 0000000000..ec91f6fc0c --- /dev/null +++ b/doc/userguide/rules/smtp-keywords.rst @@ -0,0 +1,19 @@ +SMTP Keywords +============= + +.. role:: example-rule-options + +file.name +--------- + +The ``file.name`` keyword can be used at the SMTP application level. + +Signature Example: + +.. container:: example-rule + + alert smtp any any -> any any (msg:"SMTP file.name usage"; \ + :example-rule-options:`file.name; content:"winmail.dat";` \ + classtype:bad-unknown; sid:1; rev:1;) + +For additional information on the ``file.name`` keyword, see :doc:`file-keywords`. \ No newline at end of file