From b9a4d508ad87eb0ad689ea8ccb396a97276d79b0 Mon Sep 17 00:00:00 2001 From: Alice Akaki Date: Fri, 28 Mar 2025 16:12:27 -0400 Subject: [PATCH] detect: add test for email.date keyword --- tests/detect-email-date/README.md | 8 ++++++++ tests/detect-email-date/test.rules | 1 + tests/detect-email-date/test.yaml | 16 ++++++++++++++++ 3 files changed, 25 insertions(+) create mode 100644 tests/detect-email-date/README.md create mode 100644 tests/detect-email-date/test.rules create mode 100644 tests/detect-email-date/test.yaml diff --git a/tests/detect-email-date/README.md b/tests/detect-email-date/README.md new file mode 100644 index 000000000..4ceb4532a --- /dev/null +++ b/tests/detect-email-date/README.md @@ -0,0 +1,8 @@ +# Test Description +Test mime email.date keyword + +## PCAP +From ../mime/mime-dec-parse-full-msg-test02/input.pcap + +## Redmine Ticket +https://redmine.openinfosecfoundation.org/issues/7591 diff --git a/tests/detect-email-date/test.rules b/tests/detect-email-date/test.rules new file mode 100644 index 000000000..f4145a482 --- /dev/null +++ b/tests/detect-email-date/test.rules @@ -0,0 +1 @@ +alert smtp any any -> any any (msg:"Test mime email date"; email.date; content:"Fri, 21 Apr 2023 05:10:36 +0000"; startswith; endswith; bsize:31; sid:1;) diff --git a/tests/detect-email-date/test.yaml b/tests/detect-email-date/test.yaml new file mode 100644 index 000000000..54585f3ba --- /dev/null +++ b/tests/detect-email-date/test.yaml @@ -0,0 +1,16 @@ +requires: + min-version: 8 + +pcap: ../mime/mime-dec-parse-full-msg-test02/input.pcap + +args: + - -k none --set stream.inline=true + +checks: +- filter: + count: 1 + match: + event_type: alert + email.date: Fri, 21 Apr 2023 05:10:36 +0000 + pcap_cnt: 13 + alert.signature_id: 1 -- 2.47.2