]>
git.ipfire.org Git - thirdparty/suricata.git/log 
Victor Julien  [Tue, 5 Mar 2024 09:02:53 +0000  (10:02 +0100)]  
detect: group content inspect keyword id's
Victor Julien  [Mon, 4 Mar 2024 11:53:35 +0000  (12:53 +0100)]  
detect: group types used in traffic variables
Victor Julien  [Sat, 2 Mar 2024 06:58:30 +0000  (07:58 +0100)]  
threshold: add by_flow support for global thresholds
Victor Julien  [Tue, 27 Feb 2024 10:06:47 +0000  (11:06 +0100)]  
detect/threshold: implement tracking 'by_flow'
Victor Julien  [Mon, 4 Mar 2024 11:29:24 +0000  (12:29 +0100)]  
util/var: add comments explaining types
Victor Julien  [Fri, 1 Mar 2024 12:30:09 +0000  (13:30 +0100)]  
util/var: remove printf; add assert
Philippe Antoine  [Mon, 17 Jun 2024 14:30:49 +0000  (16:30 +0200)]  
http2: do not expand duplicate headers
Philippe Antoine  [Thu, 25 Apr 2024 19:24:33 +0000  (21:24 +0200)]  
modbus: abort flow parsing on flood
Victor Julien  [Sun, 10 Sep 2023 06:21:02 +0000  (08:21 +0200)]  
detect: remove unnecessary detect thread flags stores
Philippe Antoine  [Sun, 23 Jun 2024 20:57:11 +0000  (22:57 +0200)]  
detect/nfs: do not free a null pointer
Jeff Lucovsky  [Thu, 21 Mar 2024 14:23:36 +0000  (10:23 -0400)]  
detect/base64: Use Rust defined modes everywhere
Jeff Lucovsky  [Sun, 25 Feb 2024 15:00:45 +0000  (10:00 -0500)]  
doc/transform: Correct typo
Jeff Lucovsky  [Fri, 23 Feb 2024 13:51:56 +0000  (08:51 -0500)]  
doc/transform: Describe the from_base64 transform
Jeff Lucovsky  [Thu, 22 Feb 2024 15:41:37 +0000  (10:41 -0500)]  
detect/transform: Add from_base64 transform
Jeff Lucovsky  [Thu, 22 Feb 2024 14:47:18 +0000  (09:47 -0500)]  
detect/transform: from_base64 option parsing
Jeff Lucovsky  [Thu, 22 Feb 2024 14:40:28 +0000  (09:40 -0500)]  
detect/parser: Refactor utility routines
Shivani Bhardwaj  [Fri, 21 Jun 2024 08:25:59 +0000  (13:55 +0530)]  
flow: declare and use constansts where possible
Shivani Bhardwaj  [Fri, 21 Jun 2024 08:12:24 +0000  (13:42 +0530)]  
flow/manager: make fn calls only when necessary
Shivani Bhardwaj  [Mon, 17 Jun 2024 10:30:13 +0000  (16:00 +0530)]  
flow/timeout: cleanup fn names and comments
Shivani Bhardwaj  [Thu, 13 Jun 2024 14:01:02 +0000  (19:31 +0530)]  
flow: remove unneeded args to fn
Shivani Bhardwaj  [Thu, 13 Jun 2024 13:45:54 +0000  (19:15 +0530)]  
flow/manager: add fn docs
Shivani Bhardwaj  [Thu, 13 Jun 2024 13:05:31 +0000  (18:35 +0530)]  
flow: add defensive check
Shivani Bhardwaj  [Thu, 13 Jun 2024 13:04:40 +0000  (18:34 +0530)]  
packetpool: use DEBUG_VALIDATE statement
Shivani Bhardwaj  [Thu, 13 Jun 2024 13:03:30 +0000  (18:33 +0530)]  
flow: use bool wherever possible
Philippe Antoine  [Fri, 21 Jun 2024 07:27:50 +0000  (09:27 +0200)]  
detect/icmp: require real packet in signatureFixes: 956c8bebd1 ("detect/prefilter: use sig mask to exclude pkt engines") 
Philippe Antoine  [Wed, 19 Jun 2024 11:42:32 +0000  (13:42 +0200)]  
detect: add to signature mask for decode events
Philippe Antoine  [Wed, 19 Jun 2024 11:39:08 +0000  (13:39 +0200)]  
detect: fix check for app_layer events
Jeff Lucovsky  [Tue, 18 Jun 2024 13:45:06 +0000  (09:45 -0400)]  
af-packet: Remove unused preprocessor define
Philippe Antoine  [Thu, 20 Jun 2024 14:18:25 +0000  (16:18 +0200)]  
output: configurable payload_length field for alerts
Philippe Antoine  [Thu, 20 Jun 2024 13:09:16 +0000  (15:09 +0200)]  
dcerpc: add app-layer metadata in alerts
Philippe Antoine  [Thu, 7 Dec 2023 09:32:03 +0000  (10:32 +0100)]  
filestore: do not try to store a file set to nostore
Philippe Antoine  [Thu, 29 Jun 2023 13:41:31 +0000  (15:41 +0200)]  
app-layer: fix -Wshorten-64-to-32 warnings
Philippe Antoine  [Thu, 23 Nov 2023 14:46:39 +0000  (15:46 +0100)]  
util: fix -Wshorten-64-to-32 warnings
Philippe Antoine  [Wed, 19 Jun 2024 14:45:03 +0000  (16:45 +0200)]  
detect: remove unused field
Victor Julien  [Sat, 1 Jun 2024 07:12:29 +0000  (09:12 +0200)]  
detect: add tls.alpn keyword
Victor Julien  [Fri, 31 May 2024 13:05:16 +0000  (15:05 +0200)]  
eve/schema: update for alpn
Victor Julien  [Fri, 31 May 2024 12:33:31 +0000  (14:33 +0200)]  
eve/tls: log ALPN for client and server
Victor Julien  [Fri, 31 May 2024 12:18:15 +0000  (14:18 +0200)]  
tls: store all ALPN records in the state
Victor Julien  [Tue, 18 Jun 2024 20:05:53 +0000  (22:05 +0200)]  
eve/schema: minor enip reformat
Jason Ish  [Tue, 18 Jun 2024 04:41:49 +0000  (22:41 -0600)]  
github-ci: run cargo update test on pull requests
Victor Julien  [Tue, 18 Jun 2024 04:54:28 +0000  (06:54 +0200)]  
detect/icmp-id: remove prefilter pseudo check
Victor Julien  [Tue, 18 Jun 2024 04:54:09 +0000  (06:54 +0200)]  
detect/dsize: remove prefilter pseudo check
Victor Julien  [Thu, 16 May 2024 10:25:07 +0000  (12:25 +0200)]  
detect/stream_size: allow match on pseudo packets
Victor Julien  [Thu, 16 May 2024 09:43:17 +0000  (11:43 +0200)]  
detect/csum: remove pseudo packet checks
Victor Julien  [Thu, 16 May 2024 09:42:27 +0000  (11:42 +0200)]  
detect/csum: general code cleanups
Victor Julien  [Tue, 30 Apr 2024 05:38:42 +0000  (07:38 +0200)]  
detect/prefilter: use sig mask to exclude pkt engines
Victor Julien  [Mon, 29 Apr 2024 18:48:32 +0000  (20:48 +0200)]  
detect/prefilter: minor function ptr cleanup
Victor Julien  [Wed, 1 May 2024 05:16:13 +0000  (07:16 +0200)]  
detect: remove pseudo checks from packet keywords
Victor Julien  [Wed, 1 May 2024 05:15:53 +0000  (07:15 +0200)]  
detect: skip pseudo packets if sig needs real pkt
Philippe Antoine  [Fri, 14 Jun 2024 08:28:24 +0000  (10:28 +0200)]  
tests: move detect http.uri tests to suricata-verify
Philippe Antoine  [Tue, 18 Jun 2024 05:30:01 +0000  (07:30 +0200)]  
fuzz: adapt target to number of keywords being dynamic
Philippe Antoine  [Mon, 17 Jun 2024 13:53:42 +0000  (15:53 +0200)]  
rust: remove unnecessary nested unsafe
Philippe Antoine  [Mon, 17 Jun 2024 13:38:11 +0000  (15:38 +0200)]  
sip: use right slice to take line from
Jason Ish  [Thu, 13 Jun 2024 20:28:23 +0000  (14:28 -0600)]  
rust/ike: prefix never read field names with _
Jason Ish  [Thu, 13 Jun 2024 20:23:28 +0000  (14:23 -0600)]  
rust: simply matches with unwrap_or_default
Jason Ish  [Thu, 13 Jun 2024 20:21:56 +0000  (14:21 -0600)]  
rust: fix clippy lint for legacy_numeric_constants
Jason Ish  [Thu, 13 Jun 2024 20:16:36 +0000  (14:16 -0600)]  
cargo: use default-features instead of default_features
Philippe Antoine  [Tue, 11 Jun 2024 12:20:16 +0000  (14:20 +0200)]  
detect/enip: move keywords to rust
Philippe Antoine  [Tue, 7 May 2024 14:13:07 +0000  (16:13 +0200)]  
detect/websocket: move keywords to rust
Philippe Antoine  [Tue, 7 May 2024 13:42:32 +0000  (15:42 +0200)]  
detect/dhcp: move keywords to rust
Philippe Antoine  [Fri, 26 Apr 2024 14:32:49 +0000  (16:32 +0200)]  
detect/snmp: move keywords to rust
Philippe Antoine  [Fri, 26 Apr 2024 14:31:47 +0000  (16:31 +0200)]  
detect: helper to have pure rust keywords
Philippe Antoine  [Tue, 11 Jun 2024 10:43:50 +0000  (12:43 +0200)]  
enip: remove unnecessary unsafe
Eric Leblond  [Wed, 8 Nov 2023 20:20:28 +0000  (21:20 +0100)]  
profiling: check packet flag first
Eric Leblond  [Wed, 8 Nov 2023 20:18:33 +0000  (21:18 +0100)]  
profiling: add option to active rules profiling at start
Lukas Sismis  [Tue, 16 Jan 2024 14:27:56 +0000  (15:27 +0100)]  
doc: port user install and build instruction from master-6.0.x
Lukas Sismis  [Thu, 11 Apr 2024 20:55:22 +0000  (22:55 +0200)]  
github-ci: add minimal build for Ubuntu and AlmaLinux
Lukas Sismis  [Thu, 11 Apr 2024 20:54:43 +0000  (22:54 +0200)]  
github-ci: remove gosu from installed packages
Lukas Sismis  [Tue, 16 Jan 2024 13:47:08 +0000  (14:47 +0100)]  
doc: update eBPF compilation instructions
Victor Julien  [Thu, 6 Jun 2024 15:38:55 +0000  (17:38 +0200)]  
doc/userguide: document iprep isset/isnotset
Victor Julien  [Thu, 6 Jun 2024 15:38:34 +0000  (17:38 +0200)]  
doc/userguide: add more operators to iprep
Victor Julien  [Thu, 6 Jun 2024 15:24:20 +0000  (17:24 +0200)]  
detect/iprep: update function naming
Victor Julien  [Mon, 13 May 2024 12:37:51 +0000  (14:37 +0200)]  
detect/iprep: implement isset and isnotset
Victor Julien  [Mon, 13 May 2024 12:37:02 +0000  (14:37 +0200)]  
reputation: minor cleanup
Victor Julien  [Mon, 13 May 2024 10:33:57 +0000  (12:33 +0200)]  
detect/iprep: update keyword parser for extendibility
Jason Ish  [Fri, 7 Jun 2024 23:28:01 +0000  (17:28 -0600)]  
misc: prefix functions with SC not Sc
Victor Julien  [Fri, 7 Jun 2024 19:02:00 +0000  (21:02 +0200)]  
detect/noalert: point noalert/alert to new doc
Victor Julien  [Thu, 6 Jun 2024 10:25:51 +0000  (12:25 +0200)]  
doc/userguide: add noalert/alert keyword docs
Victor Julien  [Thu, 6 Jun 2024 09:46:55 +0000  (11:46 +0200)]  
doc/userguide: give pcre1 to pcre2 proper heading
Victor Julien  [Fri, 12 Jan 2024 13:00:37 +0000  (14:00 +0100)]  
detect: implement 'alert' keyword as a companion to 'noalert'
Victor Julien  [Fri, 12 Jan 2024 10:14:27 +0000  (11:14 +0100)]  
detect: set ACTION_ALERT for rules that should alert
Victor Julien  [Fri, 12 Jan 2024 12:41:17 +0000  (13:41 +0100)]  
detect/alert: minor loop cleanup
Victor Julien  [Fri, 12 Jan 2024 08:51:02 +0000  (09:51 +0100)]  
detect/noalert: minor cleanup
Philippe Antoine  [Wed, 29 May 2024 11:47:15 +0000  (13:47 +0200)]  
websocket: add data frame
Juliana Fajardini  [Wed, 29 May 2024 17:26:54 +0000  (14:26 -0300)]  
userguide/upgrade: add note about alerts' increase
Juliana Fajardini  [Tue, 21 May 2024 20:35:34 +0000  (17:35 -0300)]  
dns: allow triggering raw stream reassembly
Philippe Antoine  [Fri, 17 Nov 2023 08:30:29 +0000  (09:30 +0100)]  
enip: convert to rust
Philippe Antoine  [Wed, 5 Jun 2024 11:57:32 +0000  (13:57 +0200)]  
files: remove the need for state in callbacks
Philippe Antoine  [Wed, 5 Jun 2024 11:36:46 +0000  (13:36 +0200)]  
app-layer: remove unused parameters
Philippe Antoine  [Tue, 4 Jun 2024 12:42:43 +0000  (14:42 +0200)]  
smtp/mime: look for urls in base64 message
Philippe Antoine  [Tue, 7 May 2024 13:09:28 +0000  (15:09 +0200)]  
dpdk: simplify and fix build
Philippe Antoine  [Tue, 30 Apr 2024 20:19:06 +0000  (22:19 +0200)]  
fuzz: build with dependencies on rust and c lib
Philippe Antoine  [Wed, 5 Jun 2024 09:48:54 +0000  (11:48 +0200)]  
ci: fix and test with Wunused-macros
Ticket: 6937
Completes 
ce9bfba76a785e6a02cbbe796a23be6c4e5bc553 
Shivani Bhardwaj  [Wed, 5 Jun 2024 03:25:17 +0000  (08:55 +0530)]  
eve/stats: add description for flow mgr & recycler
Victor Julien  [Wed, 5 Jun 2024 04:46:09 +0000  (06:46 +0200)]  
doc/userguide: fix rule container typoFixes: 8781e9352a6c ("doc/userguide: add documentation for SMTP frames") 
Juliana Fajardini  [Mon, 20 May 2024 16:02:45 +0000  (13:02 -0300)]  
pgsql: trigger raw stream reassembly
Juliana Fajardini  [Thu, 25 Apr 2024 01:13:35 +0000  (22:13 -0300)]  
pgsql/logger: open json object from logger function
Victor Julien  [Tue, 4 Jun 2024 10:30:12 +0000  (12:30 +0200)]  
doc/userguide: add documentation for SMTP frames
Victor Julien  [Mon, 13 Nov 2023 05:43:32 +0000  (06:43 +0100)]  
smtp/frames: initial frame support
Victor Julien  [Sun, 26 May 2024 06:40:11 +0000  (08:40 +0200)]  
flow-worker: debug output about updates