]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
dcerpc: check for app-layer metadata in alert
authorPhilippe Antoine <pantoine@oisf.net>
Thu, 20 Jun 2024 13:08:16 +0000 (15:08 +0200)
committerVictor Julien <victor@inliniac.net>
Sat, 22 Jun 2024 13:54:31 +0000 (15:54 +0200)
Ticket: 6090

tests/dcerpc/dcerpc-dce-opnum/test.yaml

index e93f2d1e4640f81596163f8c50af3c8a3c38e7e4..fb358ca939ed5d4979b87fd9b0681c8787490736 100644 (file)
@@ -13,6 +13,13 @@ checks:
       match:
         event_type: alert
         alert.signature_id: 1
+  - filter:
+      min-version: 8
+      count: 1
+      match:
+        event_type: alert
+        alert.signature_id: 1
+        dcerpc.req.opnum: 4
   - filter:
       count: 2
       match: