From: Modupe Falodun Date: Sat, 15 Jan 2022 22:53:42 +0000 (+0100) Subject: detect-modbus: add tests to modbus X-Git-Tag: suricata-6.0.5~44 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=aa11d68aea003ca67fc388e5b1b2a88afa33e4c4;p=thirdparty%2Fsuricata-verify.git detect-modbus: add tests to modbus Task: 4911 --- diff --git a/tests/modbus/test.rules b/tests/modbus/test.rules index e3411227c..961f9e954 100644 --- a/tests/modbus/test.rules +++ b/tests/modbus/test.rules @@ -3,3 +3,5 @@ alert modbus any any -> any any (msg:"Modbus function word test"; modbus: functi alert modbus any any -> any any (msg:"Modbus access test"; modbus: access read; sid:3; rev:1;) alert modbus any any -> any any (msg:"Modbus unit test"; modbus: unit 10; sid:4; rev:1;) alert modbus any any -> any any (msg:"Modbus full test"; modbus: unit >9, access read coils, address 0<>2; sid:5; rev:1;) +alert modbus any any -> any any (msg:"Modbus access write test"; modbus: access write; sid:6;) +alert modbus any any -> any any (msg:"Testing modbus code function"; modbus: function 8; sid:7;) diff --git a/tests/modbus/test.yaml b/tests/modbus/test.yaml index e8fb58dd7..815b76324 100644 --- a/tests/modbus/test.yaml +++ b/tests/modbus/test.yaml @@ -56,3 +56,13 @@ checks: match: event_type: alert alert.signature_id: 5 + - filter: + count: 3 + match: + event_type: alert + alert.signature_id: 6 + - filter: + count: 8 + match: + event_type: alert + alert.signature_id: 7