mirror of https://github.com/OISF/suricata
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Evasion scenario is - a first dummy write of one byte at offset 0 is done - the second full write of EICAR at offset 0 is then done and does not trigger detection The last write had the final value, and as we cannot "cancel" the previous write, we set an event which is then transformed into an app-layer decoder alert |
4 years ago | |
---|---|---|
.. | ||
Makefile.am | 6 years ago | |
app-layer-events.rules | 8 years ago | |
decoder-events.rules | 5 years ago | |
dhcp-events.rules | 7 years ago | |
dnp3-events.rules | 8 years ago | |
dns-events.rules | 5 years ago | |
files.rules | 5 years ago | |
http-events.rules | 5 years ago | |
http2-events.rules | 5 years ago | |
ipsec-events.rules | 6 years ago | |
kerberos-events.rules | 7 years ago | |
modbus-events.rules | 8 years ago | |
mqtt-events.rules | 5 years ago | |
nfs-events.rules | 8 years ago | |
ntp-events.rules | 8 years ago | |
smb-events.rules | 4 years ago | |
smtp-events.rules | 5 years ago | |
ssh-events.rules | 5 years ago | |
stream-events.rules | 6 years ago | |
tls-events.rules | 5 years ago |