You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide/rules
Alice Akaki 73ae6e997f detect: add ldap.responses.dn
ldap.responses.dn matches on LDAPDN from responses operations
This keyword maps the following eve fields:
ldap.responses[].search_result_entry.base_object
ldap.responses[].bind_response.matched_dn
ldap.responses[].search_result_done.matched_dn
ldap.responses[].modify_response.matched_dn
ldap.responses[].add_response.matched_dn
ldap.responses[].del_response.matched_dn
ldap.responses[].mod_dn_response.matched_dn
ldap.responses[].compare_response.matched_dn
ldap.responses[].extended_response.matched_dn
It is a sticky buffer
Supports prefiltering

Ticket: #7471
1 week ago
..
dataset-examples
dns-keywords
fast-pattern
flow-keywords
header-keywords
http-keywords
intro
normalized-buffers
payload-keywords
pcre
rule-types userguide: explain rule types and categorization 1 month ago
app-layer.rst
base64-keywords.rst
bypass-keyword.rst
config.rst
datasets.rst detect/datasets: implement unset command 5 months ago
dcerpc-keywords.rst
decode-layer.rst doc/decode-events: new: unknown event description 4 weeks ago
dhcp-keywords.rst
differences-from-snort.rst
dnp3-keywords.rst
dns-keywords.rst
enip-keyword.rst
fast-pattern-explained.rst
file-keywords.rst
flow-keywords.rst flow/pkts: allow matching on either direction 2 months ago
ftp-keywords.rst doc: Add ftp.command sticky buffer 1 month ago
header-keywords.rst
http-keywords.rst
http2-keywords.rst
ike-keywords.rst
index.rst doc/decode-events: new: unknown event description 4 weeks ago
integer-keywords.rst detect/integers: add support for negated strings when enum is used 2 weeks ago
intro.rst
ip-reputation-rules.rst
ipaddr.rst
ja-keywords.rst
kerberos-keywords.rst
ldap-keywords.rst detect: add ldap.responses.dn 1 week ago
lua-detection.rst
meta.rst requires: support requires check for keyword 3 months ago
modbus-keyword.rst
mqtt-keywords.rst
multi-buffer-matching.rst
nfs-keywords.rst
noalert.rst
payload-keywords.rst detect: absent keyword to test absence of sticky buffer 3 months ago
prefilter-keywords.rst
quic-keywords.rst
rfb-keywords.rst
rule-types.rst userguide: explain rule types and categorization 1 month ago
sip-keywords.rst doc: add new sip keywords 5 months ago
smb-keywords.rst
smtp-keywords.rst detect/smtp: smtp.rcpt_to keyword 1 month ago
snmp-keywords.rst
ssh-keywords.rst
tag.rst
thresholding.rst doc/threshold: Threshold keyword clarifications 4 weeks ago
tls-keywords.rst
transforms.rst
vlan-keywords.rst detect: add vlan.layers keyword 2 months ago
websocket-keywords.rst
xbits.rst