From: Eloy Pérez González Date: Mon, 14 Feb 2022 09:58:34 +0000 (+0100) Subject: smb-smb_version: new test X-Git-Tag: suricata-6.0.16~11 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=51a30b426043329a30d877fa681f7c946b155177;p=thirdparty%2Fsuricata-verify.git smb-smb_version: new test --- diff --git a/tests/smb-smb_version/input.pcap b/tests/smb-smb_version/input.pcap new file mode 100644 index 000000000..ca439fb84 Binary files /dev/null and b/tests/smb-smb_version/input.pcap differ diff --git a/tests/smb-smb_version/test.rules b/tests/smb-smb_version/test.rules new file mode 100644 index 000000000..f03fbc1d1 --- /dev/null +++ b/tests/smb-smb_version/test.rules @@ -0,0 +1,3 @@ + +alert tcp any any -> any any (msg:"SMB1 Request";flow:to_server;smb.version:1;sid:1;) +alert tcp any any -> any any (msg:"SMB2 Request";flow:to_server;smb.version:2;sid:2;) diff --git a/tests/smb-smb_version/test.yaml b/tests/smb-smb_version/test.yaml new file mode 100644 index 000000000..94f5a8efb --- /dev/null +++ b/tests/smb-smb_version/test.yaml @@ -0,0 +1,17 @@ +requires: + min-version: 7 + +args: +- -k none + +checks: +- filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1 +- filter: + count: 7 + match: + event_type: alert + alert.signature_id: 2