From: Alice Akaki Date: Sat, 15 Mar 2025 03:18:43 +0000 (-0400) Subject: detect: add test for mime email keywords X-Git-Tag: suricata-7.0.10~4 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=93e389fad0d44a17f740431788e7bbba16b5c9ea;p=thirdparty%2Fsuricata-verify.git detect: add test for mime email keywords Ticket: #7592 --- diff --git a/tests/detect-mime-email/README.md b/tests/detect-mime-email/README.md new file mode 100644 index 000000000..34e0d24df --- /dev/null +++ b/tests/detect-mime-email/README.md @@ -0,0 +1,8 @@ +# Test Description +Test mime email keywords + +## PCAP +From ../mime/mime-dec-parse-full-msg-test02/input.pcap + +## Redmine Ticket +https://redmine.openinfosecfoundation.org/issues/7592 diff --git a/tests/detect-mime-email/test.rules b/tests/detect-mime-email/test.rules new file mode 100644 index 000000000..ace06cdfd --- /dev/null +++ b/tests/detect-mime-email/test.rules @@ -0,0 +1,2 @@ +alert smtp any any -> any any (msg:"Test mime email from"; email.from; content:"toto "; sid:1;) +alert smtp any any -> any any (msg:"Test mime email from"; email.from; content:"toto"; startswith; content:"com>"; endswith; bsize:21; sid:2;) \ No newline at end of file diff --git a/tests/detect-mime-email/test.yaml b/tests/detect-mime-email/test.yaml new file mode 100644 index 000000000..d836d2e55 --- /dev/null +++ b/tests/detect-mime-email/test.yaml @@ -0,0 +1,23 @@ +requires: + min-version: 8 + +pcap: ../mime/mime-dec-parse-full-msg-test02/input.pcap + +args: + - -k none --set stream.inline=true + +checks: +- filter: + count: 1 + match: + event_type: alert + email.from: toto + pcap_cnt: 13 + alert.signature_id: 1 +- filter: + count: 1 + match: + event_type: alert + email.from: toto + pcap_cnt: 13 + alert.signature_id: 2