From: Philippe Antoine Date: Fri, 19 Jul 2024 09:41:18 +0000 (+0200) Subject: rfb: adds test for rules with secresult being an integer keyword X-Git-Tag: suricata-7.0.7~29 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e63e8957b6955e5e18d89488b170ef79f7c42360;p=thirdparty%2Fsuricata-verify.git rfb: adds test for rules with secresult being an integer keyword Ticket: 6723 --- diff --git a/tests/rfb-rules-8/test.rules b/tests/rfb-rules-8/test.rules new file mode 100644 index 000000000..8b7008d43 --- /dev/null +++ b/tests/rfb-rules-8/test.rules @@ -0,0 +1,5 @@ +alert rfb any any -> any any (msg:"rfb-secresult0"; rfb.secresult:0; sid:50;) +alert rfb any any -> any any (msg:"rfb-secresult1"; rfb.secresult:ok; sid:5;) +alert rfb any any -> any any (msg:"rfb-secresult2"; rfb.secresult:unknown; sid:6;) +alert rfb any any -> any any (msg:"rfb-secresult!0"; rfb.secresult:!0; sid:7;) + diff --git a/tests/rfb-rules-8/test.yaml b/tests/rfb-rules-8/test.yaml new file mode 100644 index 000000000..db3fef948 --- /dev/null +++ b/tests/rfb-rules-8/test.yaml @@ -0,0 +1,27 @@ +requires: + min-version: 8 + +pcap: ../rfb-rules/00-vnc-openwall-3.7.pcap + +checks: + - filter: + count: 1 + match: + event_type: alert + alert.signature: "rfb-secresult1" + - filter: + count: 1 + match: + event_type: alert + alert.signature: "rfb-secresult0" + + - filter: + count: 0 + match: + event_type: alert + alert.signature: "rfb-secresult2" + - filter: + count: 0 + match: + event_type: alert + alert.signature: "rfb-secresult!0"