Philippe Antoine
2205761bf6
doc: add missing "value" to entropy examples
...
Commit from Hydraze
1 month ago
Juliana Fajardini
edaa912ed9
detect: ban `replace` keyword for firewall mode
...
Ticket #8551
2 months ago
Philippe Antoine
64f003190d
doc: move more rules to dedicated css container
...
Ticket: 8372
Also remove dead code from script checking the rules
3 months ago
Philippe Antoine
15f45be672
doc: fix rules
...
Ticket: 8372
Somes rules in the doc had typos, fix them so suricata can load
them when you copy/paste the doc
4 months ago
Sven Cuyt
1246f1cf8c
doc/userguide: add link to differences-from-snort
...
Ticket: #8031 .
6 months ago
Sven Cuyt
a0cc534471
doc/userguide: fix table showing example payload
...
Ticket: #8031 .
6 months ago
Sven Cuyt
2d662538e5
doc/userguide: add example with non-zero offset for relative isdataat
...
Ticket: #8031 .
6 months ago
Victor Julien
7c5285e5e6
doc/userguide: explain isdataat absolute vs relative difference
...
Ticket: #8031 .
6 months ago
Jeff Lucovsky
45a36e961f
doc/byte_jump: Clarify bitmask operation
...
Issue: 6693
Clarify how the bitmask value is used for byte_jump
Snort compatibility says:
- The bitmask value is applied to the extracted value before the
multiplier is applied.
- The result of the bitmask operation is to be right shifted by the
number of trailing 0's in the bitmask value.
6 months ago
Victor Julien
73a873ecfe
doc/userguide: endswith can be mixed with offset/distance/within
...
Bug: #5030 .
7 months ago
Jeff Lucovsky
a300df4c4d
detect/entropy: Clarify when entropy is logged
...
Clarify when entropy values are logged and associated with non-alert log
records.
1 year ago
Eric Leblond
751f3eef3b
doc/userguide: fix some typos
1 year ago
Eric Leblond
9873c5d2e1
doc/userguide: add dataset with json
1 year ago
Jeff Lucovsky
a8a3780276
doc/entropy: Document the entropy log output
1 year ago
Juliana Fajardini
c5b9277474
doc/payload: fix typo, minor formatting changes
1 year ago
Jeff Lucovsky
ed2a81dc05
doc/entropy: Add documentation for the entropy keyword
...
This commits adds documentation for the entropy keyword.
The entropy keyword calculates the Shannon entropy value for content
with the calculated value used to determine whether an alert occurs.
1 year ago
Philippe Antoine
4ec90bd227
detect: absent keyword to test absence of sticky buffer
...
Ticket: 2224
It takes an argument to match only if the buffer is absent,
or it can still match if the buffer is present, but we test
the absence of some content.
For multi buffers, absent matches if there are 0 buffers.
For file keywords, absent matches if there is no file.
2 years ago
Victor Julien
c83e3285ae
doc/userguide: give pcre1 to pcre2 proper heading
2 years ago
jason taylor
876dfb99ca
doc: update http.content_len keyword information
...
Ticket: 3025
Signed-off-by: jason taylor <jtfas90@gmail.com>
2 years ago
jason taylor
fd46175203
doc: update http primer information
...
ticket: 3025
Signed-off-by: jason taylor <jtfas90@gmail.com>
2 years ago
Juliana Fajardini
244a35d539
userguide: fix explanation about bsize ranges
...
Our code handles Uint ranges as exclusive, but for bsize, our
documentation stated that they're inclusive.
Cf. from uint.rs:
DetectUintMode::DetectUintModeRange => {
if val > x.arg1 && val < x.arg2 {
return true;
}
}
Task #6708
3 years ago
Philippe Antoine
b8bc2c7e0f
doc: integer keywords
...
Ticket: 6628
Document the generic detection capabilities for integer keywords.
and make every integer keyword pointing to this section.
3 years ago
Philippe Antoine
4933b817aa
doc: fix byte_test examples
...
As this keyword has 4 mandatory arguments, and some examples
had only three...
Ticket: 6629
3 years ago
Jeff Lucovsky
47e268d609
detect/byte_math: Document bytes variable name
...
Issue: 6145
Document that byte_math accepts a variable name for bytes (optional)
3 years ago
Jeff Lucovsky
3a4554fc2b
detect/byte-jump: Document var usage for nbytes
...
Issue: 6105
3 years ago
Jeff Lucovsky
73b943276e
doc/byte_test: Document byte_test variable usage
...
Issue: 6144
This commit updates the byte_test documentation now that a variable name
can be used for the nbytes value.
3 years ago
Victor Julien
c0d9b3c078
doc/userguide: spelling
3 years ago
Jeff Lucovsky
fd46c93a8f
doc/byte_math: Add divide by 0 discussion.
...
Issue: 5945
3 years ago
Jeff Lucovsky
35bbdf4124
doc/content: Add limits for distance/within
...
Ticket: 5740
3 years ago
Jeff Lucovsky
197ad51138
doc: Update bsize documentation
...
This commit updates the bsize documentation
1. Describe what happens when "content" immediately precedes "bsize"
2. Include the operators and
3. Include examples using the operators.
4 years ago
Jeff Lucovsky
192a31c74e
doc: Fixup byte* entries to display tables properly
4 years ago
jason taylor
c29942c029
userguide: update dsize documentation/examples
...
Signed-off-by: jason taylor <jtfas90@gmail.com>
4 years ago
jason taylor
ca9e9009ba
doc: add bsize keyword examples
...
Signed-off-by: jason taylor <jtfas90@gmail.com>
4 years ago
Philippe Antoine
fae7389ae2
pcre2: document the behavioral changes
5 years ago
Joshua Lumb
cf9b2b5fd1
detect-dsize: Add ! operator for dsize matching
5 years ago
Andreas Herz
a5f36eccf1
doc: add documentation for rawbytes keyword
5 years ago
Jeff Lucovsky
901fbae7b9
doc: Add byte_math documentation
6 years ago
Jeff Lucovsky
59cc3c6281
doc: Update byte_extract doc
6 years ago
Jeff Lucovsky
4ad6c5421a
doc: fix documentation typos
6 years ago
Jeff Lucovsky
bc01392e93
doc: Update byte_test documentation
6 years ago
jason taylor
1666bc0ad1
doc: minor capitalization fix
...
Signed-off-by: jason taylor <jtfas90@gmail.com>
7 years ago
jason taylor
4f7dc4f136
doc: add bsize documentation and rule example
...
Signed-off-by: jason taylor <jtfas90@gmail.com>
7 years ago
Travis Green
3f146cdd7e
doc: add endswith keyword docs
7 years ago
Andreas Herz
30fd80b0ef
doc: convert fancy quotes to straight quotes
7 years ago
Bryant Smith
398133b6ce
doc: add byte_* documentation to the userguide
...
Added byte_test, byte_jump and byte_extract description and example rules
8 years ago
Pascal Delalande
f2dca46382
doc: fix minor typo
8 years ago
Pascal Delalande
e3c5784dd5
doc: minor updates (tls custom, TODO removal, ftp/smb file rules)
8 years ago
Victor Julien
07738af868
detect/content: introduce startswith modifier
...
Add startswith modifier to simplify matching patterns at the start
of a buffer.
Instead of:
content:"abc"; depth:3;
This enables:
content:"abc"; startswith;
Especially with longer patterns this makes the intention of the rule
more clear and eases writing the rules.
Internally it's simply a shorthand for 'depth:<pattern len>;'.
Ticket https://redmine.openinfosecfoundation.org/issues/742
9 years ago
Ralph Broenink
722cff1862
doc: Restructure ToC
...
* All sections up to 2 levels deep are now shown regardless of whether they are a separate page
* Rename Xbits and Thresholding for more consistent naming
* Minor adjustment in the Payload Keywords section
9 years ago
Ralph Broenink
e9b25988ba
doc: Move pcre entirely to Payload Keywords section
...
(plus remove lingering screenshot of a rule)
9 years ago