From: Victor Julien Date: Fri, 4 Apr 2025 15:29:07 +0000 (+0200) Subject: tests: add app-layer-state test X-Git-Tag: suricata-7.0.11~104 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=d380e421b885be7db8db10061ae6e9c63b7b23f5;p=thirdparty%2Fsuricata-verify.git tests: add app-layer-state test --- diff --git a/tests/detect-app-layer-state-01/test.rules b/tests/detect-app-layer-state-01/test.rules new file mode 100644 index 000000000..672a9f445 --- /dev/null +++ b/tests/detect-app-layer-state-01/test.rules @@ -0,0 +1,2 @@ +alert tls any any -> any any (app-layer-state: any any (app-layer-state:client_hello_done; sid:2;) diff --git a/tests/detect-app-layer-state-01/test.yaml b/tests/detect-app-layer-state-01/test.yaml new file mode 100644 index 000000000..8e69c5d29 --- /dev/null +++ b/tests/detect-app-layer-state-01/test.yaml @@ -0,0 +1,24 @@ +requires: + min-version: 8 + +pcap: ../tls/tls-client-hello-frag-01/dump_mtu300.pcap + +args: +- -k none +- --simulate-ips + +checks: +- filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1 +- filter: + count: 2 + match: + event_type: alert + alert.signature_id: 2 +- filter: + count: 1 + match: + event_type: tls