alert smtp any any -> any any (msg:"SMTP helo GP"; smtp.helo; content:"GP"; sid:1; rev:1;)
alert smtp any any -> any any (msg:"SMTP mail_from"; smtp.mail_from; content:"<gurpartap@patriots.in>"; sid:2; rev:1;)
-
+alert smtp any any -> any any (msg:"SMTP rcpt_to"; smtp.rcpt_to; content:"<raj_deol2002in@yahoo.co.in>"; sid:3; rev:1;)
# signatures not matching
alert smtp any any -> any any (msg:"SMTP helo not triggering"; smtp.helo; content:"not there"; sid:10; rev:1;)
alert smtp any any -> any any (msg:"SMTP not mail_from"; smtp.mail_from; content:"spammer"; sid:12; rev:1;)
+alert smtp any any -> any any (msg:"SMTP no rcpt_to"; smtp.rcpt_to; content:"<gurpartap@patriots.in>"; sid:13; rev:1;)
count: 0
match:
event_type: alert
- alert.signature_id: 12
\ No newline at end of file
+ alert.signature_id: 12
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ smtp.rcpt_to[0]: "<raj_deol2002in@yahoo.co.in>"
+ alert.signature_id: 3
+- filter:
+ count: 0
+ match:
+ event_type: alert
+ alert.signature_id: 13
\ No newline at end of file