From: Alice Akaki Date: Sat, 22 Mar 2025 01:27:58 +0000 (-0400) Subject: detect: add test for email.cc keyword X-Git-Tag: suricata-7.0.11~142 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=91f0a8e08531da14846a519c1921c3f2e1058b8f;p=thirdparty%2Fsuricata-verify.git detect: add test for email.cc keyword Ticket: #7588 --- diff --git a/tests/detect-email-cc/README.md b/tests/detect-email-cc/README.md new file mode 100644 index 000000000..31aadd233 --- /dev/null +++ b/tests/detect-email-cc/README.md @@ -0,0 +1,8 @@ +# Test Description +Test mime email.cc keyword + +## PCAP +From ../smtp-to-comma/10.7.29.101_49898-178.63.41.150_25.pcap + +## Redmine Ticket +https://redmine.openinfosecfoundation.org/issues/7588 diff --git a/tests/detect-email-cc/test.rules b/tests/detect-email-cc/test.rules new file mode 100644 index 000000000..765a8dde2 --- /dev/null +++ b/tests/detect-email-cc/test.rules @@ -0,0 +1 @@ +alert smtp any any -> any any (msg:"Test mime email cc"; email.cc; content:"\"jam,abrakadabra.ch\" "; startswith; endswith; bsize:44; sid:1;) diff --git a/tests/detect-email-cc/test.yaml b/tests/detect-email-cc/test.yaml new file mode 100644 index 000000000..a352b7feb --- /dev/null +++ b/tests/detect-email-cc/test.yaml @@ -0,0 +1,16 @@ +requires: + min-version: 8 + +pcap: ../smtp-to-comma/10.7.29.101_49898-178.63.41.150_25.pcap + +args: + - -k none --set stream.inline=true + +checks: +- filter: + count: 1 + match: + event_type: alert + email.cc[0]: "\"jam,abrakadabra.ch\" " + pcap_cnt: 18 + alert.signature_id: 1