]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
dhcp: adds test about leasetime keyword
authorPhilippe Antoine <contact@catenacyber.fr>
Mon, 4 Jul 2022 12:36:57 +0000 (14:36 +0200)
committerVictor Julien <victor@inliniac.net>
Tue, 13 Sep 2022 09:45:40 +0000 (11:45 +0200)
tests/dhcp-eve-extended/min7.rules [new file with mode: 0644]
tests/dhcp-eve-extended/suricata.yaml
tests/dhcp-eve-extended/test.yaml

diff --git a/tests/dhcp-eve-extended/min7.rules b/tests/dhcp-eve-extended/min7.rules
new file mode 100644 (file)
index 0000000..841a842
--- /dev/null
@@ -0,0 +1 @@
+alert dhcp any any -> any any (msg:"small DHCP lease time (<2hours)"; dhcp.leasetime:<7200; sid:1; rev:1;)
index 7f2fafa6367a03aeff0626523a489f76ddbf1ea2..cba2138a3228d91a15b1ca52cd487bcf9073f5eb 100644 (file)
@@ -6,6 +6,7 @@ outputs:
       enabled: true
       filename: eve.json
       types:
+        - alert
         - dhcp:
             extended: true
         - flow
index 68644dc0136cb4b4176dc585f6547e9bc123579d..58782b34eb770bd755bf527b76629b3a6934932f 100644 (file)
@@ -57,7 +57,6 @@ checks:
       dest_port: 67
       event_type: flow
       flow.age: 0
-      flow.alerted: false
       flow.bytes_toclient: 350
       flow.bytes_toserver: 342
       flow.pkts_toclient: 1
@@ -67,3 +66,9 @@ checks:
       proto: UDP
       src_ip: 10.16.1.4
       src_port: 68
+- filter:
+    min-version: 7
+    count: 1
+    match:
+      event_type: alert
+      alert.signature_id: 1