--- /dev/null
+# Description
+
+Test quic ietf v1 parsing
+
+# PCAP
+
+The pcap comes from https://www.bortzmeyer.org/quic.html
--- /dev/null
+alert quic any any -> any any (msg:"QUIC SNI"; quic.sni; content:"msquic.net"; sid:4;)
+alert quic any any -> any any (msg:"QUIC JA3"; ja3.string; content:"771,4866,43-51-41"; sid:3;)
--- /dev/null
+requires:
+ min-version: 7.0.0
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: quic
+ quic.extensions[1].name: "server_name"
+ quic.extensions[1].values[0]: "msquic.net"
+ quic.extensions[2].name: "alpn"
+ quic.extensions[2].values[0]: "h3-29"
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 4
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 3