You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/rules
Philippe Antoine fbc856f14d smb: adds file overlap event against evasions
Evasion scenario is
- a first dummy write of one byte at offset 0 is done
- the second full write of EICAR at offset 0 is then done
and does not trigger detection

The last write had the final value, and as we cannot "cancel"
the previous write, we set an event which is then transformed into
an app-layer decoder alert
5 years ago
..
Makefile.am rules: install dhcp-events.rules; order alphabetically 6 years ago
app-layer-events.rules app-layer: protocol change API 8 years ago
decoder-events.rules rules: add mpls packet too small decoder rule 6 years ago
dhcp-events.rules dhcp: add dhcp app-layer rules file 7 years ago
dnp3-events.rules rules: add missing classtypes for event.rules 8 years ago
dns-events.rules rules: add missing classtypes for event.rules 8 years ago
files.rules doc: minor updates (tls custom, TODO removal, ftp/smb file rules) 7 years ago
http-events.rules http: sets compression bomb limit 6 years ago
ipsec-events.rules rules: fix event names for ikev2 (weak authentication and DH parameters) 7 years ago
kerberos-events.rules Kerberos 5: rename weak crypto to weak encryption, and log it 7 years ago
modbus-events.rules rules: add missing classtypes for event.rules 8 years ago
nfs-events.rules rust/nfs: implement events 8 years ago
ntp-events.rules Add event rules for NTP events 8 years ago
smb-events.rules smb: adds file overlap event against evasions 5 years ago
smtp-events.rules smtp/mime: Set event when name exceeds limit 5 years ago
stream-events.rules flow/stream: 'wrong thread' as stream event & counter 7 years ago
tls-events.rules tls: increase max number of tls records per packet 9 years ago