]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
dcerpc: test ifaces as a part of dcerpc request
authorShivani Bhardwaj <shivanib134@gmail.com>
Wed, 19 Feb 2025 07:57:17 +0000 (13:27 +0530)
committerVictor Julien <victor@inliniac.net>
Fri, 21 Feb 2025 13:57:17 +0000 (14:57 +0100)
tests/dcerpc/dcerpc-dce-iface-01/test.yaml

index 8b8c969edf37c02e165c4c91cfeed050ef76bd7e..99ab19ecc575f231cd8ecf33c9586becb777db0d 100644 (file)
@@ -1,14 +1,18 @@
-requires:
-  min-version: 6
-  features:
-    - HAVE_LIBJANSSON
-
 args:
 - -k none
 
 checks:
   - filter:
+      min-version: 6
       count: 2
       match:
         event_type: alert
         alert.signature_id: 1
+  - filter:
+      min-version: 8
+      count: 1
+      match:
+        event_type: dcerpc
+        dcerpc.request: REQUEST
+        dcerpc.interfaces[0].uuid: "367abb81-9844-35f1-ad32-98f038001003"
+        dcerpc.call_id: 20