From: Philippe Antoine Date: Wed, 19 Nov 2025 12:35:34 +0000 (+0100) Subject: files: add checks about hashes X-Git-Tag: suricata-7.0.14~36 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=9b920500623bd381c2290deb7bf52bce4c66d090;p=thirdparty%2Fsuricata-verify.git files: add checks about hashes --- diff --git a/tests/file-match-crossed/suricata.yaml b/tests/file-match-crossed/suricata.yaml new file mode 100644 index 000000000..4a1c832d7 --- /dev/null +++ b/tests/file-match-crossed/suricata.yaml @@ -0,0 +1,12 @@ +%YAML 1.1 +--- + +outputs: + - eve-log: + enabled: yes + filetype: regular #regular|syslog|unix_dgram|unix_stream|redis + filename: eve.json + types: + - files: + force-hash: [sha256] + - alert \ No newline at end of file diff --git a/tests/file-match-crossed/test.yaml b/tests/file-match-crossed/test.yaml index 073e724f0..9804a570f 100644 --- a/tests/file-match-crossed/test.yaml +++ b/tests/file-match-crossed/test.yaml @@ -45,3 +45,16 @@ checks: match: event_type: alert alert.signature_id: 8 + + - filter: + min-version: 9 + count: 1 + match: + event_type: fileinfo + fileinfo.sha256: c345c434702129224a0a3e89810a7ed2556718221c0d36fdb7e52b93fa732b00 + - filter: + min-version: 9 + count: 1 + match: + event_type: fileinfo + fileinfo.sha256: 0605686b5f3a54d2fe07b3b6ed039779911f43ff079d7ff6fecbf4f75bf5ee10