Victor Julien
							
						 
						
							 
							
							
							
								
							
								372fc26739 
								
							
								 
							
						 
						
							
							
								
								ci: buildbot is decommissioned, so remove prscript refs  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Sascha Steinbiss
							
						 
						
							 
							
							
							
								
							
								15c42e0d83 
								
							
								 
							
						 
						
							
							
								
								doc: add documentation for SRV DNS JSON structure  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								096dce4bba 
								
							
								 
							
						 
						
							
							
								
								http2: allow filestore to work with HTTP2  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								4e242645be 
								
							
								 
							
						 
						
							
							
								
								doc: explicit header normalization further  
							
							 
							
							... 
							
							
							
							And their concatenation as described in RFC 2616 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								6b30890de9 
								
							
								 
							
						 
						
							
							
								
								doc: http.uri.raw has no spaces  
							
							 
							
							... 
							
							
							
							as they are in the protocol
cf bug #2881  
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								7b4ac8dbab 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: update http keywords  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								ca47d75c80 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: explain --strict-rule-keywords  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								a18a9d3046 
								
							
								 
							
						 
						
							
							
								
								doc: New sticky buffer icmpv4.hdr  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Phil Young
							
						 
						
							 
							
							
							
								
							
								76de981574 
								
							
								 
							
						 
						
							
							
								
								napatech: Added comment indicating that hba will be deprecated  
							
							 
							
							... 
							
							
							
							HBA will be deprecated in Suricata 7 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								3030a3da18 
								
							
								 
							
						 
						
							
							
								
								doc: provide eve 1 deprecation date  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								c95850c6ce 
								
							
								 
							
						 
						
							
							
								
								doc/rules: document config rule option  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								6f9b7e052a 
								
							
								 
							
						 
						
							
							
								
								doc/eve: Update threaded filename examples  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								f70e1f571e 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: add info about --set and lists  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								69fffb2dc4 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: include man page even when not including pdf  
							
							 
							
							... 
							
							
							
							Fix a mistake in Makefile.am where the man page was only being
added to the distribution if the PDF was also created. It should
be included even if the PDF cannot be included. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								87617b200c 
								
							
								 
							
						 
						
							
							
								
								doc/datasets: add info about memcap and hashsize  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								7d44e80a50 
								
							
								 
							
						 
						
							
							
								
								doc: document removal of unified2  
							
							 
							
							... 
							
							
							
							And suggest an alternate tool, Meer if compatibility with
Barnyard2 style databases is required.
Redmine ticket:
https://redmine.openinfosecfoundation.org/issues/3497  
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								e71f2b22fa 
								
							
								 
							
						 
						
							
							
								
								doc: add removal of individual json loggers  
							
							 
							
							... 
							
							
							
							Add link to multiple eve instances as a replacement for this
feature. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								9b5c923327 
								
							
								 
							
						 
						
							
							
								
								http: disables lzma by default for HTTP  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								e1ecb7dc41 
								
							
								 
							
						 
						
							
							
								
								doc/datasets: explain reloads, general improvements  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Simon Dugas
							
						 
						
							 
							
							
							
								
							
								48da18b081 
								
							
								 
							
						 
						
							
							
								
								doc: dns - document additional fields in eve event  
							
							 
							
							... 
							
							
							
							Documentation of additional fields for soa and sshfp. Also some minor
doc fixes and updates. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								06f41f608c 
								
							
								 
							
						 
						
							
							
								
								doc: Improve grammar, spelling and clarifications  
							
							 
							
							... 
							
							
							
							This commit improves the overall documentation's grammar, spelling, and
adds clarifications  where needed. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								b21160a6e3 
								
							
								 
							
						 
						
							
							
								
								doc: http.host keyword note for matching on port  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Roland Fischer
							
						 
						
							 
							
							
							
								
							
								de7c7eeff0 
								
							
								 
							
						 
						
							
							
								
								doc: Add dev code-style  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Odin Jenseg
							
						 
						
							 
							
							
							
								
							
								4549505418 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: fix outdated xdp info  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								999af4f62a 
								
							
								 
							
						 
						
							
							
								
								http2: adds documentation  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								James Dutrisac
							
						 
						
							 
							
							
							
								
							
								8d5e54c046 
								
							
								 
							
						 
						
							
							
								
								pcap: recusively reading pcaps / documentation  
							
							 
							
							... 
							
							
							
							Changes to doc/userguide/partials/options.rst for feature 2363
   (reading pcaps recursively) 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Sascha Steinbiss
							
						 
						
							 
							
							
							
								
							
								4e1a41a17d 
								
							
								 
							
						 
						
							
							
								
								output-json: add MAC address output  
							
							 
							
							... 
							
							
							
							This commit adds MAC address output to the EVE-JSON format. We follow the
remarks made in Redmine ticket #962 : for packets, log MAC src/dst as a
scalar field in EVE; for flows, log MAC src/dst as lists in EVE. Field names
are different between flow and packet context to avoid type confusion
(src_mac vs. src_macs). Configuration approach and JSON representation is
taken from previous GitHub PR #2700 . 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Sascha Steinbiss
							
						 
						
							 
							
							
							
								
							
								c31360070b 
								
							
								 
							
						 
						
							
							
								
								rust/mqtt: add MQTT parser  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								a5d30a3220 
								
							
								 
							
						 
						
							
							
								
								doc/output: Document multithreaded eve option  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								1569f3e349 
								
							
								 
							
						 
						
							
							
								
								transform: adds url_decode keyword  
							
							 
							
							... 
							
							
							
							Fixes https://redmine.openinfosecfoundation.org/issues/2689 
Adds a new source file to handle this keyword.
And modifies documentation, Makefile, and registration accordingly.
url_decode decodes url-encoded data, ie replacing '+' with space
and '%HH' with its value. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								00cc3c7374 
								
							
								 
							
						 
						
							
							
								
								eve/ssh: change hassh logging format  
							
							 
							
							... 
							
							
							
							Elastic search didn't accept the 'hassh' and 'hassh.string'. It would
see the first 'hassh' as a string and split the second key into a
object 'hassh' with a string member 'string'. So two different types
for 'hassh', so it rejected it.
This patch mimics the ja3(s) logging by creating a 'hassh' object
with 2 members: 'hash', which holds the md5 representation, and
'string' which holds the string representation. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Tristan Fletcher
							
						 
						
							 
							
							
							
								
							
								6cbb4d4909 
								
							
								 
							
						 
						
							
							
								
								doc: fix spelling in flowbits image  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								e04d48c8c8 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: fix outdated mpm info  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								04d88e7012 
								
							
								 
							
						 
						
							
							
								
								doc/suricata-update: fix typo and do minor cleanups  
							
							 
							
							... 
							
							
							
							Thanks to showipintbri PR 4465. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								901fbae7b9 
								
							
								 
							
						 
						
							
							
								
								doc: Add byte_math documentation  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								496306e6a9 
								
							
								 
							
						 
						
							
							
								
								doc: update stream-depth description  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								ec07f58705 
								
							
								 
							
						 
						
							
							
								
								doc: update file-store stream depth description  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Vadym Malakhatko
							
						 
						
							 
							
							
							
								
							
								a80f705d4b 
								
							
								 
							
						 
						
							
							
								
								userguide: add documentation for Hassh usage  
							
							 
							
							... 
							
							
							
							1. Rules keywords
2. Json keywords
3. Usage in lua
4. Enabling in configuration file 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								b116a56a32 
								
							
								 
							
						 
						
							
							
								
								doc: Correct typos  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								59cc3c6281 
								
							
								 
							
						 
						
							
							
								
								doc: Update byte_extract doc  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								297f91479e 
								
							
								 
							
						 
						
							
							
								
								doc: Fix spelling error  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								06f414d66d 
								
							
								 
							
						 
						
							
							
								
								doc/manpage: improve intro, add examples  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								75727c05e0 
								
							
								 
							
						 
						
							
							
								
								doc/manpage: add --reject-dev option  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								82ac72782d 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: update app-proto list  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								e6330c354d 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: list valid rule actions  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								5e4aa5b851 
								
							
								 
							
						 
						
							
							
								
								doc: Improve tos description  
							
							 
							
							... 
							
							
							
							This commit improves the description of the `tos` keyword by emphasizing
that the value used should adhere to the guidelines in RFC2474. Instead
of specifying the DSCP value directly, right shift the DSCP value and
use that. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								3005dca3fd 
								
							
								 
							
						 
						
							
							
								
								doc: pcrexform documentation  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								a77662bdbf 
								
							
								 
							
						 
						
							
							
								
								userguide: remove old drop-log documentation  
							
							 
							
							... 
							
							
							
							Redmine issue:
https://redmine.openinfosecfoundation.org/issues/2381  
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								8997a114cb 
								
							
								 
							
						 
						
							
							
								
								userguide: RDP now enabled by default  
							
							 
							
							... 
							
							
							
							Redmine issue:
https://redmine.openinfosecfoundation.org/issues/3255  
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								3eb0461abd 
								
							
								 
							
						 
						
							
							
								
								userguide: SIP now enabled by default  
							
							 
							
							... 
							
							
							
							Redmine issue:
https://redmine.openinfosecfoundation.org/issues/3256  
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								d0526e71c0 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: add IPS with BPF info, minor cleanups  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								6b8320d1c0 
								
							
								 
							
						 
						
							
							
								
								doc: document file-store v1 to v2 configuration changes  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								6850dbc852 
								
							
								 
							
						 
						
							
							
								
								suricata.yaml: remove filestore v1 configuration  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								e5fd47dcfd 
								
							
								 
							
						 
						
							
							
								
								doc/devguide: create basic layout  
							
							 
							
							... 
							
							
							
							Issue: #3343  
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								0dd1b2a616 
								
							
								 
							
						 
						
							
							
								
								doc: typo: http.server_body should be http.response_body  
							
							 
							
							... 
							
							
							
							Thanks to Jason Williams for pointing this out. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								a611ae2102 
								
							
								 
							
						 
						
							
							
								
								doc/perf: minor improvements  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Andreas Herz
							
						 
						
							 
							
							
							
								
							
								1d9db2b5f9 
								
							
								 
							
						 
						
							
							
								
								doc: add performance analysis section  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Sascha Steinbiss
							
						 
						
							 
							
							
							
								
							
								5598ff5bb3 
								
							
								 
							
						 
						
							
							
								
								doc/install: refer to buster as Debian stable  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Todd Mortimer
							
						 
						
							 
							
							
							
								
							
								6b4d32c6bb 
								
							
								 
							
						 
						
							
							
								
								doc: Update documentation for by_rule and by_both thresholds.  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								5f71e7a371 
								
							
								 
							
						 
						
							
							
								
								doc/devguide: Submission and style  
							
							 
							
							... 
							
							
							
							This commit adds code submission and coding style guidelines to the
devguide. Most of the material is a straight port from the wiki but
there have been some content modifications and additions. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								752e4828d7 
								
							
								 
							
						 
						
							
							
								
								devguide: include sources in EXTRA_DIST  
							
							 
							
							... 
							
							
							
							Required for distcheck to pass, and required to build docs
from a dist archive. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								e97cdb48f3 
								
							
								 
							
						 
						
							
							
								
								decode/teredo: implement port support  
							
							 
							
							... 
							
							
							
							Implement support for limiting Teredo detection and decoding to specific
UDP ports, with 3544 as the default.
If no ports are specified, the old behaviour of detecting/decoding on any
port is still in place. This can also be forced by specifying 'any' as the
port setting. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								4ad6c5421a 
								
							
								 
							
						 
						
							
							
								
								doc: fix documentation typos  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								bc01392e93 
								
							
								 
							
						 
						
							
							
								
								doc: Update byte_test documentation  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Frank Honza
							
						 
						
							 
							
							
							
								
							
								1c8943dedd 
								
							
								 
							
						 
						
							
							
								
								add RFB parser  
							
							 
							
							... 
							
							
							
							This commit adds support for the Remote Framebuffer Protocol (RFB) as
used, for example, by various VNC implementations. It targets the
official versions 3.3, 3.7 and 3.8 of the protocol and provides logging
for the RFB handshake communication for now. Logged events include
endpoint versions, details of the security (i.e. authentication)
exchange as well as metadata about the image transfer parameters.
Detection is enabled using keywords for:
 - rfb.name: Session name as sticky buffer
 - rfb.sectype: Security type, e.g. VNC-style challenge-response
 - rfb.secresult: Result of the security exchange, e.g. OK, FAIL, ...
The latter could be used, for example, to detect brute-force attempts
on open VNC servers, while the name could be used to map unwanted VNC
sessions to the desktop owners or machines.
We also ship example EVE-JSON output and keyword docs as part of the
Sphinx source for Suricata's RTD documentation. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								ccfdcb55fb 
								
							
								 
							
						 
						
							
							
								
								devguide: document new app-layer retvals  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								6251deae21 
								
							
								 
							
						 
						
							
							
								
								doc: adds doc for ipv4.hdr signature keyword  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								1cd314c500 
								
							
								 
							
						 
						
							
							
								
								detect: adds icmpv6.mtu keyword  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								e14447d594 
								
							
								 
							
						 
						
							
							
								
								docs/napatech: Correct typo  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								c5cee05169 
								
							
								 
							
						 
						
							
							
								
								doc: Fix typo Generate -> Generator  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								7b1699c5a8 
								
							
								 
							
						 
						
							
							
								
								doc: Add chassis for dev docs  
							
							 
							
							... 
							
							
							
							Closes redmine ticket 3344. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								8396333493 
								
							
								 
							
						 
						
							
							
								
								detect: adds icmpv6.hdr keyword  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								af1361a988 
								
							
								 
							
						 
						
							
							
								
								doc: add missing documentation for ipv6.hdr keyword  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								d3f6a95b56 
								
							
								 
							
						 
						
							
							
								
								doc: removed unified2 output  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								8c132c0b87 
								
							
								 
							
						 
						
							
							
								
								doc: Correct RST quote usage  
							
							 
							
							... 
							
							
							
							Corrects misplaced backticks preventing proper formatting of `mpm-algo`
section. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								3385859176 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: Update for dump-features  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Phil Young
							
						 
						
							 
							
							
							
								
							
								3fbcacf9a8 
								
							
								 
							
						 
						
							
							
								
								napatech: documentation hardware based bypass support  
							
							 
							
							... 
							
							
							
							Napatech hardware bypass support enables Suricata to utilize
capabilities of Napatech SmartNICs to selectively bypass flow-based
traffic. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								700eebaecc 
								
							
								 
							
						 
						
							
							
								
								doc/conf: Update copyright and regex for version  
							
							 
							
							... 
							
							
							
							Make the new regex in compliance with the modern autoconf syntax.
Closes redmine ticket #3423  
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								1666bc0ad1 
								
							
								 
							
						 
						
							
							
								
								doc: minor capitalization fix  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								4f7dc4f136 
								
							
								 
							
						 
						
							
							
								
								doc: add bsize documentation and rule example  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Daisu
							
						 
						
							 
							
							
							
								
							
								fccdb1c642 
								
							
								 
							
						 
						
							
							
								
								doc/commandline: -i option is useable several times  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Steven Hostetler
							
						 
						
							 
							
							
							
								
							
								4ac5ab00b7 
								
							
								 
							
						 
						
							
							
								
								doc/install: fix geoip typo  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								411dd69e92 
								
							
								 
							
						 
						
							
							
								
								doc/eve: layout and formatting fixes  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Williams
							
						 
						
							 
							
							
							
								
							
								55a36c79ff 
								
							
								 
							
						 
						
							
							
								
								doc: update http keywords documentation  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								95237f9894 
								
							
								 
							
						 
						
							
							
								
								docs: update datasets examples  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								EmilienCourt
							
						 
						
							 
							
							
							
								
							
								50bb8d4cb2 
								
							
								 
							
						 
						
							
							
								
								doc: fix typo on example  
							
							 
							
							... 
							
							
							
							Quotes have been forgotten in the dnp3.data example, which throws an
SC_ERR_INVALID_SIGNATURE(39) if used like in the example. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								9ef2f81ee7 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: fix typo  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								821d590f5b 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: fix base64 example  
							
							 
							
							... 
							
							
							
							Add a sticky buffer example and fix the content modifier one. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Pascal Delalande
							
						 
						
							 
							
							
							
								
							
								8e6a2bd42e 
								
							
								 
							
						 
						
							
							
								
								doc: removal of disable-rust and path typo for suricatasc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								d5ae68afc2 
								
							
								 
							
						 
						
							
							
								
								doc: fix version in install doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								1c27a99827 
								
							
								 
							
						 
						
							
							
								
								doc: add upgrade page  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								718fcbb682 
								
							
								 
							
						 
						
							
							
								
								doc: document eve/dns v2 as the default  
							
							 
							
							... 
							
							
							
							Adds eve/dns v2 format documentation. Update legacy format
to require the version field. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								6921608673 
								
							
								 
							
						 
						
							
							
								
								http: updates suricata.yaml comments  
							
							 
							
							... 
							
							
							
							As well as the userguide documentation about suricata.yaml 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								9111b9df57 
								
							
								 
							
						 
						
							
							
								
								doc: cleanup enging logging  
							
							 
							
							... 
							
							
							
							Attempt cleanup the engine logging a bit.
Also a include a verbatim excerpt of the default configuration
here for reference purposes. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								c97195bf0b 
								
							
								 
							
						 
						
							
							
								
								doc: -v verbose option documentation update  
							
							 
							
							... 
							
							
							
							Update -v documentation to reflect the new behaviour discussed
in bug #1851  where -v changes the log level to fixed levels
instead of an offset of the default log level configured
in suricata.yaml. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Konstantin Klinger
							
						 
						
							 
							
							
							
								
							
								808ea0dba9 
								
							
								 
							
						 
						
							
							
								
								app-layer: remove obsolete msn protocol detection  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								6d2bd6607e 
								
							
								 
							
						 
						
							
							
								
								datasets: make clear the feature is experimental  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								17c3e22ecd 
								
							
								 
							
						 
						
							
							
								
								doc/eve.alert: Expand metadata description  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								4061bf5ceb 
								
							
								 
							
						 
						
							
							
								
								doc/datasets: update example config to map  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								029683cbac 
								
							
								 
							
						 
						
							
							
								
								doc: reformat linux ips guide  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								6d9416148b 
								
							
								 
							
						 
						
							
							
								
								doc: add nftables IPS configuration  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								82eb669205 
								
							
								 
							
						 
						
							
							
								
								doc: information about scaling AF_PACKET IPS mode  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								ffe81dc9f2 
								
							
								 
							
						 
						
							
							
								
								doc: add info about AF_PACKET IPS  
							
							 
							
							... 
							
							
							
							Based on https://home.regit.org/2012/09/new-af_packet-ips-mode-in-suricata/ 
Also fix some typo in Netfilter setup. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								0cd5452194 
								
							
								 
							
						 
						
							
							
								
								doc: mark independent json loggers as deprecated  
							
							 
							
							... 
							
							
							
							This is the loggers such as alert-json-log, dns-json-log, etc.
They are not even referenced in the default configuration file,
and are easily replaced with multiple eve instances. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								212252faf2 
								
							
								 
							
						 
						
							
							
								
								doc/drop.log: mark as deprecated and scheduled to be removed  
							
							 
							
							... 
							
							
							
							Also make sure options are in sync with those in
suricata.yaml. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								5345379d14 
								
							
								 
							
						 
						
							
							
								
								doc/unified2: add deprecation/removal notice  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								873bc290bc 
								
							
								 
							
						 
						
							
							
								
								doc/filestore(v1) - make deprecation text a note  
							
							 
							
							... 
							
							
							
							Highlights that is is deprecated in the HTML output. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								7f32822843 
								
							
								 
							
						 
						
							
							
								
								doc/filestore(v1) - document force-filestore field  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								44a59b78c7 
								
							
								 
							
						 
						
							
							
								
								doc/anomaly Remove event_no  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								be6cdd37f8 
								
							
								 
							
						 
						
							
							
								
								stream: remove fix stream.depth references  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Peter Manev
							
						 
						
							 
							
							
							
								
							
								10819ed892 
								
							
								 
							
						 
						
							
							
								
								doc: Update tuning considerations doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Peter Manev
							
						 
						
							 
							
							
							
								
							
								6df1001957 
								
							
								 
							
						 
						
							
							
								
								doc: Update high performance config doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								bd2f1e15fd 
								
							
								 
							
						 
						
							
							
								
								doc/stats: minor clarrifications on 5.0 defaults  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								42438ec08e 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: add quickstart to dist  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Giuseppe Longo
							
						 
						
							 
							
							
							
								
							
								dd5d0afd79 
								
							
								 
							
						 
						
							
							
								
								doc: add SIP keywords  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								d3e2cc9926 
								
							
								 
							
						 
						
							
							
								
								doc: document dns.opcode keyword  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								daed788d49 
								
							
								 
							
						 
						
							
							
								
								doc: Replace dns_query with dns.query.  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Giuseppe Longo
							
						 
						
							 
							
							
							
								
							
								972be0a560 
								
							
								 
							
						 
						
							
							
								
								doc: update file-extraction section  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Travis Green
							
						 
						
							 
							
							
							
								
							
								798d874662 
								
							
								 
							
						 
						
							
							
								
								doc: fix whitespace  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								6aa2d550a1 
								
							
								 
							
						 
						
							
							
								
								doc/dotprefix: fix example rules  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								ab3d6328ba 
								
							
								 
							
						 
						
							
							
								
								detect/transform: add dotprefix keyword to doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								df325d63ea 
								
							
								 
							
						 
						
							
							
								
								doc/eve.anomaly: fix indent and general formatting  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								075592b66f 
								
							
								 
							
						 
						
							
							
								
								doc: Simplified anomaly configuration settings  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								aaacbf28c2 
								
							
								 
							
						 
						
							
							
								
								logging/anomaly: Support configuration filter types  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								35bc73e4e2 
								
							
								 
							
						 
						
							
							
								
								doc: change eBPF directory path  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Zach Kelly
							
						 
						
							 
							
							
							
								
							
								caef8b5b38 
								
							
								 
							
						 
						
							
							
								
								protocol parser: rdp  
							
							 
							
							... 
							
							
							
							Initial implementation of feature 2314:
1. Add protocol parser for RDP
2. Add transactions for RDP negotiation
3. Add eve logging of transactions 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Andreas Herz
							
						 
						
							 
							
							
							
								
							
								d657fd9bf0 
								
							
								 
							
						 
						
							
							
								
								doc: add quickstart guide  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								d5009c5d8c 
								
							
								 
							
						 
						
							
							
								
								doc/stream: briefly explain bypass  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								0bb07b550c 
								
							
								 
							
						 
						
							
							
								
								userguide: remove section on using Oinkmaster  
							
							 
							
							... 
							
							
							
							Users should be using Suricata-Update now. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Travis Green
							
						 
						
							 
							
							
							
								
							
								3f146cdd7e 
								
							
								 
							
						 
						
							
							
								
								doc: add endswith keyword docs  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Travis Green
							
						 
						
							 
							
							
							
								
							
								9f8dcad287 
								
							
								 
							
						 
						
							
							
								
								doc: update of ssh-kewords documentation  
							
							 
							
							... 
							
							
							
							Modifies ssh-keywords.rst to fix syntax error in example rule as well as
update descriptions to indicate older keywords have been deprecated. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								9488002a0d 
								
							
								 
							
						 
						
							
							
								
								doc: use describe instead of option for old Sphinx  
							
							 
							
							... 
							
							
							
							Older versions of Sphinx will generate duplicate IDs when you have
options like:
.. option:: some-option
.. option:: some-other-option
The version of Sphinx provided on CentOS 7 has this issue, newer
versions of Sphinx do not.  As CentOS 7 is still a popular
distribution, change ".. option" to ".. describe" which has the
same visual output, but does not generate links. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								e36a963196 
								
							
								 
							
						 
						
							
							
								
								datasets/doc: minor fixes and clarifications  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								0107b9a057 
								
							
								 
							
						 
						
							
							
								
								doc/dataset: initial documentation  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								1bc738fbe4 
								
							
								 
							
						 
						
							
							
								
								doc: typo fixes  
							
							 
							
							... 
							
							
							
							By @espritlibre and @Zeal0us 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Nick Price
							
						 
						
							 
							
							
							
								
							
								d0a85b7550 
								
							
								 
							
						 
						
							
							
								
								ja3: Mention LibNSS dependency for JA3  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								cc28d24e9a 
								
							
								 
							
						 
						
							
							
								
								doc: install eBPF files in share directory  
							
							 
							
							... 
							
							
							
							Following proposal by Sascha Steinbiss, let's use /usr/share/suricata
to store the eBPF files. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								3cf49ae868 
								
							
								 
							
						 
						
							
							
								
								doc: fix English and some typos  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								4be6701836 
								
							
								 
							
						 
						
							
							
								
								doc: pointer to bpfctrl  
							
							 
							
							... 
							
							
							
							As bpfctrl is currently the easiest way to manage pinned maps,
let's point to it. We will switch doc to suricatacl once support
has been added. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								8f1a7de791 
								
							
								 
							
						 
						
							
							
								
								doc: improve doc on compiling with eBPF support  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								f1ab27b7cb 
								
							
								 
							
						 
						
							
							
								
								doc: improve XDP cpu redirect documentation  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								6d9ac64f7b 
								
							
								 
							
						 
						
							
							
								
								doc: only balance by ip pair  
							
							 
							
							... 
							
							
							
							As there is some issue with defrag, let's recommend to only do
IP pair load-balacing for RSS 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								a1d3835b86 
								
							
								 
							
						 
						
							
							
								
								doc: document filter.bpf changes  
							
							 
							
							... 
							
							
							
							Also adds some info to explain maps. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								08397e07f1 
								
							
								 
							
						 
						
							
							
								
								doc: fix typos in geoip doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								0d5608bab2 
								
							
								 
							
						 
						
							
							
								
								doc: fix display of icmp code and type array  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								0c84591afe 
								
							
								 
							
						 
						
							
							
								
								doc: use a table to list direction filter in geoip  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								c01cadbade 
								
							
								 
							
						 
						
							
							
								
								doc: fix geoip syntax  
							
							 
							
							... 
							
							
							
							Spaces are not allowed before country code. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Vinjar Hillestad
							
						 
						
							 
							
							
							
								
							
								4c18fee3c6 
								
							
								 
							
						 
						
							
							
								
								Documenting base64_decode and base64_content  
							
							 
							
							... 
							
							
							
							base64 doc changes based on #4027  pull feedback 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Hilko Bengen
							
						 
						
							 
							
							
							
								
							
								36998ab4cd 
								
							
								 
							
						 
						
							
							
								
								Add documentation for --with-clang parameter  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Andreas Herz
							
						 
						
							 
							
							
							
								
							
								c0bddff078 
								
							
								 
							
						 
						
							
							
								
								userguide: remove old reference to rule-reload option  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								a66383569c 
								
							
								 
							
						 
						
							
							
								
								userguide: formatting: remove tabs  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								c68510437f 
								
							
								 
							
						 
						
							
							
								
								userguide: ftp formatting updates  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								2149807bd6 
								
							
								 
							
						 
						
							
							
								
								eve/ftp: Transaction support for unmatched requests  
							
							 
							
							... 
							
							
							
							Modified transaction logic to create a new transaction with each
request; replies location transactions by using the oldest "open"
(unmatched) transaction or the last transaction if none are open. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								1930b1f504 
								
							
								 
							
						 
						
							
							
								
								eve/ftp: Log FTP transactions  
							
							 
							
							... 
							
							
							
							This changeset includes changes that
1. Add transaction support to the FTP parser
2. Support eve json logging of FTP transactions 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Bill Meeks
							
						 
						
							 
							
							
							
								
							
								a291209e47 
								
							
								 
							
						 
						
							
							
								
								detect/geoip: migrate to GeoIP2 database format  
							
							 
							
							... 
							
							
							
							Issue #2765  
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								034555644b 
								
							
								 
							
						 
						
							
							
								
								doc: add tcp.hdr and udp.hdr  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								a01df4b86b 
								
							
								 
							
						 
						
							
							
								
								doc: document tcp.mss keyword  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								6cd39c5cfb 
								
							
								 
							
						 
						
							
							
								
								userguide: Document app-layer anomaly items  
							
							 
							
							... 
							
							
							
							This changeset expands the anomaly section to include newly added
app-layer items. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								1f151dd8a6 
								
							
								 
							
						 
						
							
							
								
								doc: address norg comments on eBPF doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eloïse Brocas
							
						 
						
							 
							
							
							
								
							
								8692aac97f 
								
							
								 
							
						 
						
							
							
								
								doc: specify config file in ebpf doc  
							
							 
							
							... 
							
							
							
							This patch updates the ebpf-xdp.rst file to specify which
configuration file has to be modified. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								eea3c6b610 
								
							
								 
							
						 
						
							
							
								
								doc: info for new bypass counters  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								e3dccb2400 
								
							
								 
							
						 
						
							
							
								
								doc: update bypass stats doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								dbf3606169 
								
							
								 
							
						 
						
							
							
								
								doc: document flow event_type  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								8a11581ac8 
								
							
								 
							
						 
						
							
							
								
								doc: update ebpf doc following bypass_filter change  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								253c011c70 
								
							
								 
							
						 
						
							
							
								
								doc: update for latest xdp_filter.c change  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								567b5ee1bc 
								
							
								 
							
						 
						
							
							
								
								af-packet: rename option 'no-percpu-hash'  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								ca50f8852e 
								
							
								 
							
						 
						
							
							
								
								doc: improve ebpf doc  
							
							 
							
							... 
							
							
							
							Add example of bypass rules and explain clang dependency. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								c11eb78141 
								
							
								 
							
						 
						
							
							
								
								doc: document netronome hardware bypass usage  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								82c4f5135b 
								
							
								 
							
						 
						
							
							
								
								doc: use github mirror to setup libbpf  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								1c4d214cdb 
								
							
								 
							
						 
						
							
							
								
								doc: typo fixes on ebpf doc  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								b7560d7547 
								
							
								 
							
						 
						
							
							
								
								doc: document externally managed global switch  
							
							 
							
							... 
							
							
							
							This is currently implemented as an exposed map and it seems
a good way to do it. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								b1769d5f8f 
								
							
								 
							
						 
						
							
							
								
								util-ebpf: implement pinned maps loading  
							
							 
							
							... 
							
							
							
							Load flow tables at start if asked to. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								19c0a5edf5 
								
							
								 
							
						 
						
							
							
								
								doc: white space and typo fix  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								6d41a0ced0 
								
							
								 
							
						 
						
							
							
								
								doc: more eBPF and XDP capabilities  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								315c29a8e6 
								
							
								 
							
						 
						
							
							
								
								ebpf: change the logic to avoid ktime usage  
							
							 
							
							... 
							
							
							
							Kernel time is not available (and/or costly) on NIC such as
Netronome so we update the logic to detect dead flows based on a
lack of update of packets counters. This way, the XDP filter will
be usable by network card.
This patch also updates the ebpf code to support per CPU and
regular mapping. Netronome is not supporting it and the structure
is using atomic for counter so the cost of simultaneous update
is really low.
This patch also updates the xdp_filter to be able to select if the
flow table is per CPU on shared. Second option will be used for
hardward offload. To deactivate the per cpu hash, you need to set
USE_PERCPU_HASH to 0.
This patch also adds an new option to af-packet named no-percpu-hash
If this option is set to yes then the Flow bypassed manager thread
will use one CPU instead of the number of cores. By doing that
we are able to handle the case where USE_PERCPU_HASH is unset (so
hardware offload for Netronome).
This patch also remove aligment indications in the eBPF filter. This
was not really needed and it seems it is causing problem with
some recent version of LLVM toolchain. 
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Andreas Herz
							
						 
						
							 
							
							
							
								
							
								30fd80b0ef 
								
							
								 
							
						 
						
							
							
								
								doc: convert fancy quotes to straight quotes  
							
							 
							
							
							
						 
						
							6 years ago  
						
					 
				
					
						
							
							
								 
								Pierre Chifflier
							
						 
						
							 
							
							
							
								
							
								9dfec7e734 
								
							
								 
							
						 
						
							
							
								
								SNMP: add the "snmp.pdu_type" detection keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Pierre Chifflier
							
						 
						
							 
							
							
							
								
							
								e1dd19a0eb 
								
							
								 
							
						 
						
							
							
								
								SNMP: add the "snmp.community" detection keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Pierre Chifflier
							
						 
						
							 
							
							
							
								
							
								aa608e0ca2 
								
							
								 
							
						 
						
							
							
								
								SNMP: add the "snmp.version" detection keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								ab1d95446a 
								
							
								 
							
						 
						
							
							
								
								doc: http keyword update  
							
							 
							
							... 
							
							
							
							This changeset updates the keyword type for http.location and http.server 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								0960ca0d00 
								
							
								 
							
						 
						
							
							
								
								detect/analyzer Add missing HTTP values  
							
							 
							
							... 
							
							
							
							This changeset adds recognition of missing HTTP values
- Raw host
- Header names
- Server body
- User agent 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								b59e82a642 
								
							
								 
							
						 
						
							
							
								
								userguide: add documentation for ja3s.string keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								76b94c7073 
								
							
								 
							
						 
						
							
							
								
								userguide: add documentation for ja3s.hash keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								d15903a2ef 
								
							
								 
							
						 
						
							
							
								
								userguide: add documentation for Ja3SGetString Lua function  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								37a0594417 
								
							
								 
							
						 
						
							
							
								
								userguide: add documentation for JA3SGetHash Lua function  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								800608ab65 
								
							
								 
							
						 
						
							
							
								
								userguide: add JA3S fields to the TLS logger documentation  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								8a94b93b7b 
								
							
								 
							
						 
						
							
							
								
								doc: Anomaly logging documentation  
							
							 
							
							... 
							
							
							
							This changeset adds discussion of anomaly log records and
the anomaly log record format. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								7020cffaa8 
								
							
								 
							
						 
						
							
							
								
								userguide: 'sticky' instead of 'Sticky' for all tls keywords  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								03d986dd55 
								
							
								 
							
						 
						
							
							
								
								userguide: add documentation for tls.certs keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								7d6875fb68 
								
							
								 
							
						 
						
							
							
								
								documentation: Correct rst for ssh-keywords  
							
							 
							
							... 
							
							
							
							This changeset corrects an error in the ssh-keywords
where 3 "`" characters were used instead of 2 "`" characters. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								97fc7c1e1a 
								
							
								 
							
						 
						
							
							
								
								documentation: sticky buffer updates  
							
							 
							
							... 
							
							
							
							This changeset updates the userguide for the TLS and JA3
keywords that have been renamed from <id>_<name> to <id.name> 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Giuseppe Longo
							
						 
						
							 
							
							
							
								
							
								76357350fd 
								
							
								 
							
						 
						
							
							
								
								doc: update http.protocol description  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								4705314fd2 
								
							
								 
							
						 
						
							
							
								
								doc: Add manpages for suricatasc and suricatactl  
							
							 
							
							... 
							
							
							
							Add the missing manpages and the corresponding Sphinx configuration
for the command line tools `suricatasc` and `suricatactl`.
Closes redmine ticket #884 . 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								360a6ace43 
								
							
								 
							
						 
						
							
							
								
								doc: add info about buffer usage in lua  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								355d125c4f 
								
							
								 
							
						 
						
							
							
								
								userguide: remove dns-log  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								75a018ead2 
								
							
								 
							
						 
						
							
							
								
								doc: remove autoconf replacement var for Rust  
							
							 
							
							... 
							
							
							
							Set to yes as Rust is always enabled now. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Phil Young
							
						 
						
							 
							
							
							
								
							
								6cfc39d7c9 
								
							
								 
							
						 
						
							
							
								
								napatech: auto-config documentation update  
							
							 
							
							... 
							
							
							
							Added documentation describing how to configure suricata to automaticly
configure sreams and host buffers without using NTPL.  I.e. from
suricata.yaml. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								9856c5533a 
								
							
								 
							
						 
						
							
							
								
								doc: ssh.{proto,software} documentation update  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								74cd6a9ee8 
								
							
								 
							
						 
						
							
							
								
								doc: add http.location and http.server  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Pascal Delalande
							
						 
						
							 
							
							
							
								
							
								bde65467a9 
								
							
								 
							
						 
						
							
							
								
								doc: add ssh protocol in eve log section  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								96c6cf98d5 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: add 3rd-party-integration to dist  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								f1c83c3308 
								
							
								 
							
						 
						
							
							
								
								doc/userguide: new 3rd party section, add bluecoat  
							
							 
							
							... 
							
							
							
							Add Symantec SSLV (bluecoat) doc to new 3rd party section for
documenting integrating Suricata with 3rd party tools. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Bryant Smith
							
						 
						
							 
							
							
							
								
							
								398133b6ce 
								
							
								 
							
						 
						
							
							
								
								doc: add byte_* documentation to the userguide  
							
							 
							
							... 
							
							
							
							Added byte_test, byte_jump and byte_extract description and example rules 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								d6903e70c1 
								
							
								 
							
						 
						
							
							
								
								file-log: remove and add warning  
							
							 
							
							... 
							
							
							
							Feature was deprecated and scheduled for removal.
Ticket #2376  
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								83a8df90f3 
								
							
								 
							
						 
						
							
							
								
								doc: improvement of xbits documentation page  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								43ede4db7f 
								
							
								 
							
						 
						
							
							
								
								doc: xbits:noalert is not a valid syntax  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								2483331a5d 
								
							
								 
							
						 
						
							
							
								
								doc/unix-socket: Add missing commands and detail  
							
							 
							
							... 
							
							
							
							Add missing commands and their corresponding details in unix-socket
userguide.
Closes redmine ticket #2800  
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								c47164ebc8 
								
							
								 
							
						 
						
							
							
								
								doc: add table for custom values of eve/http  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								6fcd2db043 
								
							
								 
							
						 
						
							
							
								
								tile: remove files  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								517b45ea2d 
								
							
								 
							
						 
						
							
							
								
								netmap: switch to nm_* API  
							
							 
							
							... 
							
							
							
							Process multiple packets at nm_dispatch. Use zero copy for workers
recv mode.
Add configure check netmap check for API 11+ and find netmap api version.
Add netmap guide to the userguide. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Maurizio Abba
							
						 
						
							 
							
							
							
								
							
								6c0ec0b2f3 
								
							
								 
							
						 
						
							
							
								
								eve/http: add request/response http headers  
							
							 
							
							... 
							
							
							
							Add a keyword configuration dump-all-headers, with allowed values
{both, request, response}, dumping all HTTP headers in the eve-log http
object. Each header is a single object in the list request_headers
(response_headers) with the following notation:
{
    "name": <header name>,
    "value": <header value>
}
To avoid forged malicious headers, the header name size is capped at 256
bytes, the header value size at 2048.
By default, dump-all-headers is disabled. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Maurizio Abba
							
						 
						
							 
							
							
							
								
							
								4697351188 
								
							
								 
							
						 
						
							
							
								
								smtp: create raw-extraction feature  
							
							 
							
							... 
							
							
							
							Add a raw-extraction option for smtp. When enabled, this feature will
store the raw e-mail inside a file, including headers, e-mail content,
attachments (base64 encoded). This content is stored in a normal File *,
allowing for normal file detection.
It'd also allow for all-emails extraction if a rule has
detect-filename:"rawmsg" matcher (and filestore).
Note that this feature is in contrast with decode-mime.
This feature is disabled by default, and will be disabled automatically
if decode-mime is enabled. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								eb73008ccf 
								
							
								 
							
						 
						
							
							
								
								detect/transform: add to_sha1 keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								75f9c1ae9f 
								
							
								 
							
						 
						
							
							
								
								detect/transform: add to_md5 keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								b3c021f8d0 
								
							
								 
							
						 
						
							
							
								
								userguide: improve stats logging documentation  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Pascal Delalande
							
						 
						
							 
							
							
							
								
							
								f2dca46382 
								
							
								 
							
						 
						
							
							
								
								doc: fix minor typo  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								7a121d9b4c 
								
							
								 
							
						 
						
							
							
								
								doc: add _static dir to make dist  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Travis Green
							
						 
						
							 
							
							
							
								
							
								c2adb9e669 
								
							
								 
							
						 
						
							
							
								
								doc: added tos keyword  
							
							 
							
							... 
							
							
							
							Redmine issue:
https://redmine.openinfosecfoundation.org/issues/2583  
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								9dd925a46a 
								
							
								 
							
						 
						
							
							
								
								userguide/install: add rust, python-yaml to ubuntu  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								fc395eb2c5 
								
							
								 
							
						 
						
							
							
								
								userguide: updated hyperscan version reference  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								131112de13 
								
							
								 
							
						 
						
							
							
								
								doc: Remove gulp references  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								fc54d750dd 
								
							
								 
							
						 
						
							
							
								
								doc: add bypass keyword documentation  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								be8c06adfd 
								
							
								 
							
						 
						
							
							
								
								userguide: add documentation for ssl_version keyword  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								85f2486e0b 
								
							
								 
							
						 
						
							
							
								
								multi-tenant: document per tenant settings  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								5afeebf884 
								
							
								 
							
						 
						
							
							
								
								doc/flow: updates and cleanups to flow section  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								72dd4a5f92 
								
							
								 
							
						 
						
							
							
								
								doc/rules: initial transforms documentation  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								226fe5cab3 
								
							
								 
							
						 
						
							
							
								
								doc/performance: redo runmodes explanation  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								17e2d39531 
								
							
								 
							
						 
						
							
							
								
								doc/install: update Rust info in generic install overview  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								473688746b 
								
							
								 
							
						 
						
							
							
								
								doc/eve: add community id  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								e92fda37c9 
								
							
								 
							
						 
						
							
							
								
								doc: add documentation for SSH keywords  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Pascal Delalande
							
						 
						
							 
							
							
							
								
							
								64922a476e 
								
							
								 
							
						 
						
							
							
								
								doc: remove deprecated force-md5 flag from userguide  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								jason taylor
							
						 
						
							 
							
							
							
								
							
								7f4e5e6eac 
								
							
								 
							
						 
						
							
							
								
								userguide: update hyperscan documentation  
							
							 
							
							... 
							
							
							
							Signed-off-by: jason taylor <jtfas90@gmail.com> 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								4d38d0844b 
								
							
								 
							
						 
						
							
							
								
								doc: add documentation for Lua function 'TlsGetVersion'  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Mats Klepsland
							
						 
						
							 
							
							
							
								
							
								10fcc8d2ca 
								
							
								 
							
						 
						
							
							
								
								doc: update tls.version documentation  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Maurizio Abba
							
						 
						
							 
							
							
							
								
							
								bce7c2dd87 
								
							
								 
							
						 
						
							
							
								
								eve/http: add tx->request_port_number as http_port  
							
							 
							
							... 
							
							
							
							Add the port specified in the hostname (if any) to the http object in
eve. The port may be different from the dest_port used by the TCP flow. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								173e5a1c58 
								
							
								 
							
						 
						
							
							
								
								doc: iprep supports CIDR networks  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								7c884e0850 
								
							
								 
							
						 
						
							
							
								
								doc: update multi-tentant for device feature  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Danny Browning
							
						 
						
							 
							
							
							
								
							
								2dc6b6ee14 
								
							
								 
							
						 
						
							
							
								
								source-pcap-file: delete when done (2417)  
							
							 
							
							... 
							
							
							
							https://redmine.openinfosecfoundation.org/issues/2417 
Add option to have pcap files deleted after they have been processed.
This option combines well with pcap file continuous and streaming
files to a directory being processed. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								ede94e1f66 
								
							
								 
							
						 
						
							
							
								
								doc: alphabetize EXTRA_DIST  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								ff73d908aa 
								
							
								 
							
						 
						
							
							
								
								doc: add window ips inline doc to extra_dist  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								d2142cf433 
								
							
								 
							
						 
						
							
							
								
								doc: make warnings errors when building man page  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								01f477786e 
								
							
								 
							
						 
						
							
							
								
								doc: link in windows ips setup page  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jacob Masen-Smith
							
						 
						
							 
							
							
							
								
							
								ec77632e84 
								
							
								 
							
						 
						
							
							
								
								Adds WinDivert support to Windows builds  
							
							 
							
							... 
							
							
							
							Enables IPS functionality on Windows using the open-source
(LGPLv3/GPLv2) WinDivert driver and API.
From https://www.reqrypt.org/windivert-doc.html  : "WinDivert is a
user-mode capture/sniffing/modification/blocking/re-injection package
for Windows Vista, Windows Server 2008, Windows 7, and Windows 8.
WinDivert can be used to implement user-mode packet filters, packet
sniffers, firewalls, NAT, VPNs, tunneling applications, etc., without
the need to write kernel-mode code."
- adds `--windivert [filter string]` and `--windivert-forward [filter
    string]` command-line options to enable WinDivert IPS mode.
    `--windivert[-forward] true` will open a filter for all traffic. See
    https://www.reqrypt.org/windivert-doc.html#filter_language  for more
    information.
Limitation: currently limited to `autofp` runmode.
Additionally:
- `tmm_modules` now zeroed during `RegisterAllModules`
- fixed Windows Vista+ `inet_ntop` call in `PrintInet`
- fixed `GetRandom` bug (nonexistent keys) on fresh Windows installs
- fixed `RandomGetClock` building on Windows builds
- Added WMI queries for MTU 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Chris Speidel
							
						 
						
							 
							
							
							
								
							
								1e8959b465 
								
							
								 
							
						 
						
							
							
								
								doc: fix minor typo  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								693a3df031 
								
							
								 
							
						 
						
							
							
								
								tls: document encrypt-handling option  
							
							 
							
							... 
							
							
							
							Document in sample yaml and user guide. 
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								c677e07d3e 
								
							
								 
							
						 
						
							
							
								
								kerberos: minor doc updates, add author  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								fb85822730 
								
							
								 
							
						 
						
							
							
								
								dhcp: update user guide  
							
							 
							
							
							
						 
						
							7 years ago  
						
					 
				
					
						
							
							
								 
								Pierre Chifflier
							
						 
						
							 
							
							
							
								
							
								c51ff32adb 
								
							
								 
							
						 
						
							
							
								
								Document Kerberos 5 parsing events  
							
							 
							
							
							
						 
						
							8 years ago  
						
					 
				
					
						
							
							
								 
								Pierre Chifflier
							
						 
						
							 
							
							
							
								
							
								1076c7cd47 
								
							
								 
							
						 
						
							
							
								
								Add krb5_err_code detection keyword  
							
							 
							
							
							
						 
						
							8 years ago  
						
					 
				
					
						
							
							
								 
								Pierre Chifflier
							
						 
						
							 
							
							
							
								
							
								d6b9c0294a 
								
							
								 
							
						 
						
							
							
								
								Add krb5_cname and krb5_sname detection keywords  
							
							 
							
							
							
						 
						
							8 years ago