Philippe Antoine
62a186ceef
detect/rfb: move keywords to rust
...
Ticket: 7178
On the way, convert rfb.secresult to a generic integer with enumeration
cf ticket 6723
12 months ago
Victor Julien
fa9cae3899
doc/userguide: document logging changes from 6 to 7
...
Minor other logging related improvements like clarifying language and
improving formatting for pdf output.
1 year ago
Philippe Antoine
0b2ed97f36
ssh: frames support
...
Ticket: 5734
Adds frames for SSH records, that come after banner, and before
the data is encrypted.
These records may contain cipher lists for instance.
1 year ago
Giuseppe Longo
70ed9f91d8
doc: add ldap protocol
1 year ago
Philippe Antoine
bce8f4b853
detect/ssh: remove deprecated keywords
...
Ticket: 2377
1 year ago
Philippe Antoine
0a1062fad2
detect/mqtt: move keywords to rust
...
Ticket: 4863
On the way, convert some keywords to use the first-class integer
support.
And helpers for pure rust the support for multi-buffer.
Move the C unit tests about keyword mqtt.protocol_version
to unit tests for generic integer parsing, and test version 5
instead of testing twice version 3.
Also iterate all tx's messages for reason code as is done for other
keywords.
And allow detection on empty topics.
1 year ago
Jason Ish
5f516c5896
doc: add pf-ring plugin upgrade notes
...
Ticket: #7162
1 year ago
Philippe Antoine
e0fd59a20d
doc: state that payload-length includes the gaps
1 year ago
Jason Ish
4d3d57249a
doc: update dns section of the eve format documentation
1 year ago
Jason Ish
d3c08b9643
doc: upgrade guide for dns logging changes
...
Bug: #6281
1 year ago
Sascha Steinbiss
53c62432c6
doc: update MQTT configuration
1 year ago
Shivani Bhardwaj
c66f1f4488
doc: add note about datasets string memcaps
...
Bug 3910
1 year ago
Victor Julien
afc318737a
doc/userguide: document threshold backoff type
1 year ago
Victor Julien
e362a01f8d
doc/userguide: document new threshold config options
1 year ago
Victor Julien
405491c3fc
detect/detection_filter: add support for track by_flow
1 year ago
Victor Julien
3f04af7c7f
doc: add thresholding by_flow
1 year ago
Jeff Lucovsky
01e20c91fb
doc/transform: Correct typo
1 year ago
Jeff Lucovsky
d205ff82d0
doc/transform: Describe the from_base64 transform
...
Issue: 6487
Document the new transform and indicate that it's the preferred way to
perform base64 decoding (preferred over base64_decode)
1 year ago
Philippe Antoine
c9ce43b31e
output: configurable payload_length field for alerts
...
Ticket: 7098
1 year ago
Victor Julien
3d059611c3
detect: add tls.alpn keyword
...
Ticket: #7108 .
1 year ago
Victor Julien
c79a382e42
eve/tls: log ALPN for client and server
...
Part of the extended logging.
Logs `client_alpns` and `server_alpns` arrays in the tls object.
Ticket: #7055 .
1 year ago
Philippe Antoine
ae72376ebe
detect/snmp: move keywords to rust
...
Ticket: 4863
On the way, convert unit test DetectSNMPCommunityTest to a SV test.
And also, make snmp.pdu_type use a generic uint32 for detection,
allowing operators, instead of just equality.
1 year ago
Lukas Sismis
bd9608771e
doc: port user install and build instruction from master-6.0.x
...
Ticket: #6686
1 year ago
Lukas Sismis
521d1cb8e7
doc: update eBPF compilation instructions
...
Ticket: #6599
1 year ago
Victor Julien
8b42182fee
doc/userguide: document iprep isset/isnotset
1 year ago
Victor Julien
2f74d435d3
doc/userguide: add more operators to iprep
1 year ago
Victor Julien
50ef646d45
doc/userguide: add noalert/alert keyword docs
1 year ago
Victor Julien
c83e3285ae
doc/userguide: give pcre1 to pcre2 proper heading
1 year ago
Juliana Fajardini
43b998aa73
userguide/upgrade: add note about alerts' increase
...
With triggering stream reassembly early, since for certain types of
rules there may be more alerts triggered - even in IPS mode, make this
clear in the upgrading section.
Bug #7026
1 year ago
Philippe Antoine
82c03f72c3
enip: convert to rust
...
Ticket: 3958
- transactions are now bidirectional
- there is a logger
- gap support is improved with probing for resync
- frames support
- app-layer events
- enip_command keyword accepts now string enumeration as values.
- add enip.status keyword
- add keywords :
enip.product_name, enip.protocol_version, enip.revision,
enip.identity_status, enip.state, enip.serial, enip.product_code,
enip.device_type, enip.vendor_id, enip.capabilities,
enip.cip_attribute, enip.cip_class, enip.cip_instance,
enip.cip_status, enip.cip_extendedstatus
1 year ago
Victor Julien
17b32f98d7
doc/userguide: fix rule container typo
...
Fixes: 8781e9352a
("doc/userguide: add documentation for SMTP frames")
1 year ago
Victor Julien
8781e9352a
doc/userguide: add documentation for SMTP frames
1 year ago
Juliana Fajardini
aeb200e001
devguide: highlight commit message example
...
Although we have the example for a commit message in our Code Submission
Process sub-chapter, seems that people still oversee it a lot. It was
suggested that we put it in a note-box, to make it more visible.
1 year ago
Jason Ish
3eb8c728fd
doc: update lua sandbox docs for allowed packages/functions
1 year ago
Jason Ish
bc011f2205
lua: use rust crate to vendor (bundle) lua
...
Remove lua-dev(el) from all CI tests.
1 year ago
Jo Johnson
ba6a976e06
doc: Initial doc for lua sandbox
1 year ago
Jo Johnson
712496bb3f
lua: Remove luajit support
...
lua 5.4 support is not available in luajit
Ticket: #4776
1 year ago
Jo Johnson
586c92d9d5
lua: require lua 5.4
...
github-ci: Disable lua on debian 10 as it doesn't have Lua 5.4.
Ticket: #4776
1 year ago
jason taylor
47d6c3a3ab
doc: add source verification docs
...
Ticket: #6908
Signed-off-by: jason taylor <jtfas90@gmail.com>
1 year ago
Shivani Bhardwaj
719fda3967
doc: add description about tls.subjectaltname
...
Feature 5234
1 year ago
Philippe Antoine
2c305ba37e
pop3: protocol detection
...
Ticket: #6366
1 year ago
Philippe Antoine
7582b18a9f
http: configures libhtp to allow spaces in uri
...
Ticket: #2881
1 year ago
Giuseppe Longo
8a171c9d74
doc: add arp changes
1 year ago
Philippe Antoine
fcdd7f000a
detect: add options to app-layer-protocol keyword
...
Ticket: 4921
app-layer-protocol keyword accept an optional mode to precise
which protocol we want to match: toclient, toserver, final,
or original
1 year ago
Philippe Antoine
715bf048ee
frames: rust API makes tx_id explicit
...
And set it right for SIP and websocket,
so that relevant tx app-layer metadata gets logged.
Ticket: 6973
1 year ago
Shivani Bhardwaj
6d92596548
doc: add note about fast_pattern w base64_data
...
Bug 5220
1 year ago
jason taylor
abb74245cc
doc: update normalization notes
...
Ticket: #6781
Signed-off-by: jason taylor <jtfas90@gmail.com>
1 year ago
jason taylor
5dacf4d92b
doc: add http.connection ref and fix location
...
Signed-off-by: jason taylor <jtfas90@gmail.com>
1 year ago
Victor Julien
fcca5c7514
detect/iprep: update doc about 0 value
...
A value of 0 was already allowed by the rule parser, but didn't
actually work.
Bug: #6834 .
1 year ago
jason taylor
aa919f8081
doc: update flowbits information
...
Ticket: #6991
Signed-off-by: jason taylor <jtfas90@gmail.com>
1 year ago