mirror of https://github.com/OISF/suricata
doc: add file.name information to smtp keyword doc
Signed-off-by: jason taylor <jtfas90@gmail.com>pull/9985/head
parent
9d1ad0187e
commit
fc81c99b58
@ -0,0 +1,19 @@
|
|||||||
|
SMTP Keywords
|
||||||
|
=============
|
||||||
|
|
||||||
|
.. role:: example-rule-options
|
||||||
|
|
||||||
|
file.name
|
||||||
|
---------
|
||||||
|
|
||||||
|
The ``file.name`` keyword can be used at the SMTP application level.
|
||||||
|
|
||||||
|
Signature Example:
|
||||||
|
|
||||||
|
.. container:: example-rule
|
||||||
|
|
||||||
|
alert smtp any any -> any any (msg:"SMTP file.name usage"; \
|
||||||
|
:example-rule-options:`file.name; content:"winmail.dat";` \
|
||||||
|
classtype:bad-unknown; sid:1; rev:1;)
|
||||||
|
|
||||||
|
For additional information on the ``file.name`` keyword, see :doc:`file-keywords`.
|
Loading…
Reference in New Issue