From: Philippe Antoine Date: Thu, 11 Mar 2021 15:17:56 +0000 (+0100) Subject: Adds kerberos probing parser test X-Git-Tag: suricata-6.0.4~101 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=2f9db69ab6f242b9a348374abc24c85ac0f53740;p=thirdparty%2Fsuricata-verify.git Adds kerberos probing parser test --- diff --git a/tests/krb5-probing/README.md b/tests/krb5-probing/README.md new file mode 100644 index 000000000..0de6659b0 --- /dev/null +++ b/tests/krb5-probing/README.md @@ -0,0 +1,2 @@ +Test krb5 EVE probing parser +Pcap from https://redmine.openinfosecfoundation.org/issues/2809 diff --git a/tests/krb5-probing/krb.pcap b/tests/krb5-probing/krb.pcap new file mode 100644 index 000000000..a47bf6470 Binary files /dev/null and b/tests/krb5-probing/krb.pcap differ diff --git a/tests/krb5-probing/suricata.yaml b/tests/krb5-probing/suricata.yaml new file mode 100644 index 000000000..ebe86e565 --- /dev/null +++ b/tests/krb5-probing/suricata.yaml @@ -0,0 +1,10 @@ +%YAML 1.1 +--- + +outputs: + - eve-log: + enabled: true + types: + - krb5 + - alert + - anomaly diff --git a/tests/krb5-probing/test.yaml b/tests/krb5-probing/test.yaml new file mode 100644 index 000000000..cb99f153b --- /dev/null +++ b/tests/krb5-probing/test.yaml @@ -0,0 +1,20 @@ +requires: + features: + - HAVE_LIBJANSSON + - RUST + min-version: 7 + +args: + - -k none + +checks: + - filter: + count: 0 + match: + event_type: anomaly + - filter: + count: 1 + match: + event_type: krb5 + krb5.msg_type: KRB_ERROR + krb5.failed_request: KRB_AS_REQ