From: Alice Akaki Date: Fri, 31 Jan 2025 12:48:47 +0000 (-0400) Subject: detect: add test for ldap.request.dn keyword X-Git-Tag: suricata-7.0.9~34 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=f93de79af67302365b78618a145d954d8f9fdbfb;p=thirdparty%2Fsuricata-verify.git detect: add test for ldap.request.dn keyword Ticket: #7471 --- diff --git a/tests/detect-ldap-dn/README.md b/tests/detect-ldap-dn/README.md new file mode 100644 index 000000000..127a77ed6 --- /dev/null +++ b/tests/detect-ldap-dn/README.md @@ -0,0 +1,5 @@ +Test ldap.request.dn keyword. + +PCAP from ../ldap-search/ldap.pcap + +Redmine ticket: https://redmine.openinfosecfoundation.org/issues/7471 \ No newline at end of file diff --git a/tests/detect-ldap-dn/test.rules b/tests/detect-ldap-dn/test.rules new file mode 100644 index 000000000..5554354fd --- /dev/null +++ b/tests/detect-ldap-dn/test.rules @@ -0,0 +1 @@ +alert ldap any any -> any any (msg:"Test ldap request dn"; ldap.request.dn; content:"dc=example,dc=com"; startswith; endswith; sid:1;) diff --git a/tests/detect-ldap-dn/test.yaml b/tests/detect-ldap-dn/test.yaml new file mode 100644 index 000000000..c649f474b --- /dev/null +++ b/tests/detect-ldap-dn/test.yaml @@ -0,0 +1,17 @@ +requires: + min-version: 8 + +pcap: ../ldap-search/ldap.pcap + +args: + - -k none --set stream.inline=true + +checks: + - filter: + count: 1 + match: + event_type: alert + pcap_cnt: 4 + ldap.request.operation: search_request + ldap.request.search_request.base_object: dc=example,dc=com + alert.signature_id: 1