count: 1
match:
app_proto: ftp-data
- dest_ip: 192.168.100.16
- dest_port: 42987
+ src_ip: 192.168.100.16
+ src_port: 42987
event_type: fileinfo
fileinfo.filename: test.pdf
fileinfo.gaps: false
fileinfo.stored: true
fileinfo.tx_id: 0
proto: TCP
- src_ip: 192.168.100.230
- src_port: 20
+ dest_ip: 192.168.100.230
+ dest_port: 20
- filter:
count: 1
match:
app_proto: ftp-data
- dest_ip: 192.168.100.230
- dest_port: 20
+ src_ip: 192.168.100.230
+ src_port: 20
event_type: fileinfo
fileinfo.filename: test.pdf
fileinfo.gaps: false
fileinfo.stored: true
fileinfo.tx_id: 0
proto: TCP
- src_ip: 192.168.100.16
- src_port: 52407
+ dest_ip: 192.168.100.16
+ dest_port: 52407
- filter:
count: 1
match:
app_proto: ftp-data
- dest_ip: 192.168.100.230
- dest_port: 20
+ src_ip: 192.168.100.230
+ src_port: 20
event_type: fileinfo
fileinfo.filename: notepad.exe
fileinfo.gaps: false
fileinfo.stored: true
fileinfo.tx_id: 0
proto: TCP
- src_ip: 192.168.100.16
- src_port: 48902
+ dest_ip: 192.168.100.16
+ dest_port: 48902
- filter:
count: 1
match:
app_proto: ftp-data
- dest_ip: 192.168.100.16
- dest_port: 57829
+ src_ip: 192.168.100.16
+ src_port: 57829
event_type: fileinfo
fileinfo.filename: notepad.exe
fileinfo.gaps: false
fileinfo.stored: true
fileinfo.tx_id: 0
proto: TCP
- src_ip: 192.168.100.230
- src_port: 20
+ dest_ip: 192.168.100.230
+ dest_port: 20
- HAVE_NSS
args:
- - -k none --runmode=single
+- -k none
+- --runmode=single
pcap: input.pcap
checks:
-
- - filter:
- requires:
- min-version: 6
- count: 1
- match:
- event_type: fileinfo
- fileinfo.state: "CLOSED"
- fileinfo.stored: true
- fileinfo.size: 99400
- filter:
- requires:
- lt-version: 6
count: 1
match:
event_type: fileinfo
+ # TRUNCATED: fize is ~150k, we limit to 100k with stream depth
fileinfo.state: "TRUNCATED"
fileinfo.stored: true
fileinfo.size: 99400
+ src_ip: 35.209.241.59
+ src_port: 20