--- /dev/null
+# Description
+
+Test stream_size keyword as prefilter.
--- /dev/null
+alert tcp any any -> any any (flow:established,to_server; stream_size:server,<,1111; prefilter; content: "EICAR"; sid:1234;)
--- /dev/null
+pcap: ../smb-eicar-file/input.pcap
+
+requires:
+ min-version: 7
+
+# disables checksum verification
+args:
+- -k none
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1234
--- /dev/null
+# Description
+
+Test stream_size keyword as prefilter on timeout packet
+
--- /dev/null
+alert tls any any -> any any (msg:"SERVER HELLO DATA - to_client"; flow:established,to_client; tls.random; content:"|54 b8 f7 73|"; bsize:>1; stream_size:server,>,1111; prefilter; sid:1234;)
+
--- /dev/null
+pcap: ../tls/tls-random-6989/input.pcap
+
+requires:
+ min-version: 8
+
+args:
+- -k none
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1234