From e576599567aa1d33f666f49bfeea1738b76d50b1 Mon Sep 17 00:00:00 2001 From: Philippe Antoine Date: Mon, 8 Sep 2025 10:51:50 +0200 Subject: [PATCH] snmp: adds test for pdu_type keyword Ticket: 6723 --- tests/snmp-pdu-type/README.md | 7 +++++++ tests/snmp-pdu-type/test.rules | 2 ++ tests/snmp-pdu-type/test.yaml | 19 +++++++++++++++++++ 3 files changed, 28 insertions(+) create mode 100644 tests/snmp-pdu-type/README.md create mode 100644 tests/snmp-pdu-type/test.rules create mode 100644 tests/snmp-pdu-type/test.yaml diff --git a/tests/snmp-pdu-type/README.md b/tests/snmp-pdu-type/README.md new file mode 100644 index 000000000..3b436c61a --- /dev/null +++ b/tests/snmp-pdu-type/README.md @@ -0,0 +1,7 @@ +# Test Purpose + +Match on SNMP pdu_type keyword + +## PCAP + +This PCAP from snmp-v2c-get is reused diff --git a/tests/snmp-pdu-type/test.rules b/tests/snmp-pdu-type/test.rules new file mode 100644 index 000000000..03514a40b --- /dev/null +++ b/tests/snmp-pdu-type/test.rules @@ -0,0 +1,2 @@ +alert snmp any any -> any any (msg:"SNMP Test Rule"; snmp.pdu_type: get_next_request; sid:1; rev:1;) +alert snmp any any -> any any (msg:"SNMP Test Rule"; snmp.pdu_type: 1; sid:2; rev:1;) diff --git a/tests/snmp-pdu-type/test.yaml b/tests/snmp-pdu-type/test.yaml new file mode 100644 index 000000000..580f079e0 --- /dev/null +++ b/tests/snmp-pdu-type/test.yaml @@ -0,0 +1,19 @@ +requires: + min-version: 9 + +pcap: ../snmp-v2c-get/SNMPv2c_get_requests.pcap + +checks: + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1 + snmp.pdu_type: get_next_request + + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 2 + snmp.pdu_type: get_next_request -- 2.47.3