From 8d633ced74f08301afc4f3557f289895cf43e33f Mon Sep 17 00:00:00 2001 From: Victor Julien Date: Mon, 18 Jan 2021 19:22:28 +0100 Subject: [PATCH] tests: add teredo test --- tests/decode-teredo-01/README.md | 4 + tests/decode-teredo-01/input.pcap | Bin 0 -> 26297 bytes tests/decode-teredo-01/test.yaml | 567 ++++++++++++++++++++++++++++++ 3 files changed, 571 insertions(+) create mode 100644 tests/decode-teredo-01/README.md create mode 100644 tests/decode-teredo-01/input.pcap create mode 100644 tests/decode-teredo-01/test.yaml diff --git a/tests/decode-teredo-01/README.md b/tests/decode-teredo-01/README.md new file mode 100644 index 000000000..2130ed1fd --- /dev/null +++ b/tests/decode-teredo-01/README.md @@ -0,0 +1,4 @@ +PCAP +==== + +Pcap found in the Bro github https://github.com/bro/bro/blob/master/testing/btest/Traces/tunnels/Teredo.pcap diff --git a/tests/decode-teredo-01/input.pcap b/tests/decode-teredo-01/input.pcap new file mode 100644 index 0000000000000000000000000000000000000000..2eff14469d6edb8f411e072b20f8dcd744b9faf3 GIT binary patch literal 26297 zc-ri|2UHYIw>H{D0m(=bkReEtFyx$b&N(v-Fyt^qK{5!E1r*6B0wRcl2qHNuNrI9D zC4)##0s?mi^m||Z{52Yzg)rvQM0 z_}`$6LrEM98`wtt-ae~GZU9-obQTB;kOzSI=q3ONA-cBIRE$c9*iV62#Ao2WFcE5$ zHL?y-ssjL!yn=$9f`Wpqyr#U0f~>5Dyt=%Mg0zCXyq1ErEaHP`p`joruPm=6uOY7> zEB)(7MiV&IRhPL6{O64b0Oe9+;x@wwwW->aOhPv_q z0TA*H2awm**U?bc;ZT#-($mxe*fCJhh%W#HDEf~8Lxc%3BrXC12n6JQ-g$t=*Vc z!JOekA|R14SpY300s@Ixi%@2n#2o-k5GY3?cz@7Eu@1BcY7Ca zCu$MVg`hf~quda~`;#s$NL?~+p6k-BfyoMJArTNrJz9ivgdfKMzzl(+OO6KkA^?1U zhXRXkMY;xIC=x|lFh>jj9o{IQZ|sj8j9vqn)J6J_Hvuc;sT3loCn4v<6>{!l$ET=2 z4K8XVP(p+Jfr9#@-6mUY7Yiv;4bmNS;0~hh&hJbTBU}Lh?nJI$2o{zXQCr zpg*Yre1|(z2mE(+wwN2bte^asN5AYk>s{C{y<|q=>Fjp>^wT~B{7u*`|#fhi_De38HadC5k@o;3_ zT;WhxIES9UJ5&U8){N_{-Cu{)psx0C2N4jzkT4#Oz8BP!L)souF9Oo_cZEPbx%fDR zz#tZDA4_*nHx6!Y0bx-)Ry-UfH!nmJTQ^@IRfEdp|NDfHck~;i zIqvZOVvfxp<{&Wu0A!zhpq}D9oZMg>XKPnWYg=1Saj2KKrz^~p!`a#$?&f}04|5mi z7DluZ5aL9B;~@GAvvwBO6+YkegoXKdrMbDm0yv27+ImCa;^#fbL7;mfIwX#?01g~s zPH_h}7buRqwI`etaopb1+U4vRJ2wxQn;m?9zzYiZcK`QkSE#R-xFA0};@|fgA9pWt zZeBiqer_-yH~WuYJnY=(haC|D#QBBT5&ytA_TDgCaT{)H8zEb6VGbca8z=`KAFlw1 zkgzZ>2ahnXEuXM}ptY@y0FIlNxG&6=ou8eXorj%A01Rdq6cA$P3x?7{;TER z+x@*2;xXWzy^V0N(%f5rQ!_b-oK+{OK1_&EYInmqePJdz%+2a z{~OBC)H5VX-0E*pC}@^Cd=xrB%bznkrp1NBcRJ!e#X<7ZaMmOz+p zSBp><+Q4~^^70wlpHOBMLc>K8HjKMe2-C4E`$L5 z0P9mu83@XGn2XrZVeUQxnD%aN_Rdf=1j_;dHGqPI?kU9toDhwW`>)=CVxD|O3OFUQ zB|yTSc?bW65ENzhF&Ri`2m%@vxBy)EE%d)vVjxwa>j$vU4xu=A##o6Z2B#i(^0Z_mY03F4;N&2U<%`auhFJ;?b%FtiRcE6PE5oH%-2>`Ap0_X$! zx3HUn&dW^B0J_w2C3aK%Ss8^f5n0a1ZpuC{Gbsb;G6&|^O=aKP!;t64U^mtObzBL5 z1-q&Dyo_UjJiiDVX?n3T%s-9lyR%XC|9MoKd^D*3G^!})quSJf1>_RV3euoD8`ZOp{1*DZHLB78=9zwC03&i_ux(wvIIL}5V6II}z@_Mq0Du;8 zzF)vXwnD1g--iX5Aqr-{%fU3F-yJIDavZf zD%KU1cqJY&L^wyJ=m>n* z1dsz{QTQ5jP*5-dD=OHl-==0~=L7%0*&t!M5PlRi@e3&DJ>x+~Se+Ob%@76?#6&^E zB%r1{{p0z_K=%m!Pa`^VHlhyyd_--L6vl?~Ct0Isvh4rQ$l@--1#}Q+==^TZ%0*8g zWo61EW$8XbVZwhG5&?i`gwN70K$P@H+Vms4`<3;O5_}O7ED!~Y-$~Gl{_vZmQ|w{c znFL&s|58E-&>lGCRh@~{4vLT#jz~C75C=?tM-*zr?a16REenbGuiR2-I0FEJuRqp5 z8T;NZ;79uC9)A)peW{T6S1pi|Bv4WRWVy*R%gO$1IdZEX5`IPeRU%S?fFJr_mix6Y zS`5(uz(b^-fJ8@135h`TMXcfWcguS+GJTwgt!}61@#6`O6B{Uy^_Ary0Y|vwnvD)K8_& zxbKp8|EqoiS{RrNMRq<2>55jwv?okA&LqD=N+wvv0_+ec+5N81Mo4Z)^qJ$QKFe)k zpGm&--|n*_Lb|UOp^Vby0{}ou#YOZi91S?zf0c^n9sLO@^)A8RrJ`A{^dqIBasLmc zQphOPS^|KgJR&>(kq2}CNLP_pIL`Bn-+7|?_jFg?Edb{1Y|X{biAZ-1VXlbW)=Lzm zFADnp8>FEJ;^*WR1wmao^mRo+o<1VnoWeHztRO`w#L0~d8AF44c?5XCAO)Bw)XvS1 zisf<;N#c-qg}B)w@*5G5eE`gz-4<%+j0pMvby(KH z+7pqPihz`LH93TY_=P#R*}dU*971O>g6!w=1b+_jd4CP)osb8ue+2YyPB26xEgg9U zab-DiK>>atK`_LI-_DK~%xldnqNgs7NPvZTc){F!U=g+NC4PQhejyP>L`g(f9Il`U z(breCHPO>^R&cNvLRc8;0(G&0dLoiExTiN%6r_uQmeZD&mR5owzU2H}TpDOf*ELenHYO23Fx^xYJ1wt%4@1Q>g#ICdOE8qIPfcjWo#84VQzi_E>2$dhMt~w zP;~c)l|PHq8S&eDAP);iuo0sacQYVxjLLNG&v06s-qgjwyJJPcg; zZ54FE3g7@ZM94wTSwls~+1bX@5NZq+HuMv)7BY4dRCo1M2=MSVfdtqa8Sq0nbQEl4 zJv~)~ZSC~=?Y#tr)hvB@Wpr)5q007_nwoZw?z#|N2V{zcoRTnZyuXOxR|+y>h&iL6 zh@U7(ZcFn!5s3UZDabeQx~r`gAr*_nx9>z?j0ezT0B8HJQZX(u#3H3Cb^cu{2Cy`O zl#2fLe=gP1_NUAj4AN9ZxGFN8{lz0^RAU@@}CxK}7fyYP4|qVvjVXHuC;xj9)h;)v~`jf@z0g1tv6 zC(0eNqK%}y5~@br5)|haTHJ*bV1!9M zn-!9`a15Z$HEhI_1(ceP`$r2{6O>@{7#G=cFE&P4+vUicr#`(Q?HN|9>ov5dViU$Q>u9`A5z7WK~dOi8NC9g+vKoCA@bzOj|sb z>APFRkRnpio^>cxGK5pbR!}ic>QR_W{-G{7X}@Zx{n>SRJ|gtm0E$ z2Y9ruFuc;eTx}QkseOdF-l7nFB?9Kg#;bwfyZ^BsCBleP{&kxrxjO1qj_jxEpGEHO}ay7Rc}Eq*k) zCwKmu;p@-KbXNLMbT%1mx$Ai_cQ5?Cy|(bX=yk^FJXpR~SH1XqS+SnP;%*kuOTj7y zD<;+gW|vI+E~z(65NlD3GzfF8*S4#G9gvJkYV}9PymiKy9si6mop^sRCR+>QJletW z<)wYo_Sh>8!{|+gpGeZPzztXg?U7#z)>y4Rt4z3Dr-r@=Hw45tqxO#7H+`%T|B`+OO}1KRpb&?<;imrNM$wILEuqN%Ph{RJoTA6M1tP$xw)y*6a zF|x8A7(A4`hVzQJH1?fAbV`k#e_E~+A3K0!24NFAh}Inj6}}VU13gOiN-l3W;@HadHXIC%3PQ--Bx}ctmS2Yc0$scjMx%o0p;Nb z^ZqMF6GCDW+Peo3pP?W?fwy?+TUdxfK|gNEOt;X8!Am zCdVfjY+8!oC9bmDFbvED zH4YHk-Vu?RB+?<^N4dX@E^-mQnL!64^7`(DMtLicGM^ejQ^~ShTc*(!KUNF%0W|Cy zvaUl8&I^#z>iZJ6)p85LB<%1x&~G|vFND=|aX&2> zsq3;xkdzXSvhKtV^)(OOCNZ7Mqh5RA`nBmLh8dgDL_>Amt)RIRHUn`?1wMG)Q%cf< zH4TNMCX3h46Q#E)GFLQpIQ?4+hbnbQGdFVX`}_8E<8NmS0@&JZbSOyRdfgL9_99h zQi-Op&Y7yfC{wbk3pEv=2qP5=<3BqME$&Wq0(0(O*EUo9T<+d26wMU=xH#b5BXnJ_ zs%5}j+J9}~ zi^Gdy*b^&xs<)taB_G-HZ{ya%sxp&ZzH)OxX7x!ykzdKQRGs#7(fbncU-)`bjV)mv zf*HBS%fBuS!0D$_Q{7SD&O|Ha=zMy(B>R?T+;hN;a$AG5gYWa4`?`l>c5Pks!zFh( zC3EzBaz;_=oYco`fv60Zuk!lOUiUdz@9+O;E=91s#8NqqR?536sdgbN}WGt3I_Pbu#7S&Dn@pQX62whTpX>&O%r z-}XGRT|`LLLj}(EUwIl;fgujb)2g@s&eNzoYhFmHsHp#4o_1S5<7o;imTzMK&_Aq| z*wlsaqA!gLGF?UtfOHc9kwm z1B6Es_6hUOFv(4w^CxdAW(R)5sBWA zUT1t{c%+bfxTZJoI#wvip#S|t{>-oXc=VarSwa#enFq_e$323EOhUKVlqxl|o<1=C z_Ap0|w(Wt+g=vM=hwbt$v@`JA2c(!858l zsG79g98*kTF?KjwH_U)9n=$<#5%y? z?jl@VzZjb9e^-P4zqJ~Koa4_TaQ>8K#GhpuZT~FG@R$s|?lGuENM}bN_y5AWj4l-6 z?B5+vS65scEN;N#>~CVE;bv^4;;AevFA8$EhC7IVCzd}h*l>$*gMYJNqvvVu>V_)b>9w3*q6|2;2RAO{WUErXxglBGD*AM@4%*e$$k=s6%K-P1L17V-H@G zoiRDo+eZYF!c#(zpc&Z={&)@B*?ng1YwKQ?hUb7-rRCKYg5So?ZOq|k z=UoYC^`{`&iTTuX%Py#lr@I~JpkxUNL{h{?f4l0+&7T zyzcLh9X86#{mr1|b=w5+rVuu12%f*Xhi*<-gX-%^w&qG^HGo0xt7(ssz86VOE*m%> zW=6%{PPvJ)J>EWLes?qMU`Y40Wk39BJ*2DLp;n3ZE#XOS5dl^AWXh~3ogYt{rsox1 z+Ux`_aV^5Muusdki!4V}Ki_f?kzjt^5zChPnX+tc;}*&lGZ%IZc7Ztaj8w z(I8Xj>`&|u)Q;#wp5O{oTm(H05I$CT*ecB?pi=BNteGAWm3;T57$#e_PMKuNVeN*~ zv(kaFh19|YR*01(uO{S*XKE3JtN2~Tx6`!D$W$Gr+ zB(ny0rX}2abMb&3?oo|zlhDq`6k5R$@5iS?`)G7$E__)DlL^j1azg>jPnZy8JyH@o zYR^?C{LO+?yk!x!XSAn4J0~tH`qRQlBJ`>E)>QbI_L*hmy~jH;;f3*VoUo?%EIwFY z%#B}zorKu9-_VMAa%T(!_@Tu#QEuXI0=GcgxJ{7c+s@r48Sx|=-ZHmS?NNF2h51z9 ziC20zME6=tGPM;^Obc1G+D500Y`)Y8&hXAiF}lsI`~~AR`mXzjR&KnpOOG83DiUJr z)GY)TrY5Uv9up}id853`6ViJVFZLoAQ@(RX#UN?8e1K<|SD|K##0T85Ayqw=qbZhS z4b^{_a;1>8h$y<2FATf6Y&L~2!^z+5$zw025(T(k zN-|shW9*7>E4^ouESh^tWny}p+V4ChlID{;ec!H8$@@IDRMgqd5E?&nZBA7SZh!C~ zCkEywH2Ok7??(NHv}2`mrMh%&<`-QvKDkUnjQ+XP?YTNI=R)=`ppNU5%GgtBCs&1% z2SUp$vJ{5*p_UOH9iKNpyYN2r#in?h$2O&ET+Gg4x^YnZ5-*3A)qGXKf>nRrUmxc1 z@pU!#3X(BfZvBxl6V4d3^`9}OPsR_%geC$2G3B~RSE0epYnKWeSmpcg<+3nRwNF{R zQZ?c9xmuz^h4*%jRl82+jZ)majgfRiQgVQRh$scx1C|oAH`LGd?_TJ?RNPZ8eIL4T zFu*MtGNYnVrYsvX`zbK92E;rRSpUSVcg1mJCEBrB)9htuK+rLZz9PTf+-_y49;UXN z=kt$JisOkNhQ7Q&xpQ=_HtqHFe{kTY|ti((vsQ)m4?cd_ zx;58nC3sHfC2_acb|ocSW~Xi8n=RBD9psR&k&+v8t6aL_UvB(e3pUPzvd?(= za%LNDZx^oGxG|S4i7(c6jpmJ`-APUA_e_}a3!BMvS2SXlh095yj1?dry{dTK`w*uX z$PQg&xz`u0`xARl;>n5<2HIU3dHLfsUZ_jWSzEronI0-te57T*VxRm9Q}=Vn5l_vk zQPMr`J*B$SbyrEg_{xF!%WB15AxW;HfSdf4uw<#)0`m&~SM``}=Kge%Az76Xt!#L& zz@6YPaX0B9O12ndL`>wY_VrIEOyBcq=jiIbWgpM+&RrjEHyL z4M}lkynW0DB_^gFaB9vQYH4?)j3QKE=TO>q^c8Q3F1K~G#@DY(Wl1+jxRX;d--$N5 zDCLCS$rfrf4(gb`kd;(TXUY;$6;Dfht(rV<@Tpjj81ctToYZkyx8;ZfWJH{1w7R?V zW|Ievj-ct&Y1CAIUDa1zIvnR%cap9Wg|~g5N&P#I9$YY2>X*#((TXe;%3#y$UYuhm?`t?Ma7JRw`AU#3)nHlGb)L`6EBy$292{r0A>kJG> ze69vGP(#UhdH)GPtw!7dRf)%F>(^lQ3?8C=?3Haj1H-A0>K#dy6(4H4^4f-b^5)>Y z8uRM+B&X9=Y zX%)M_^E8^-7uvJzmHofV)7SOSc$$LF?gSAj=X2+hZlfO#JhoK&=&o~Xv22L^&K)%4 z^v`?Xmjfj5i=Rm>I*ZV21Jr%>^vI$Mw(9u&a2ab!TnrM@sWF(v&==#MdE;KWvt5Tt zeN_lYJpijWp3fWi?uT1`xMYs*Dg)XfTjBf<;%U%W^VD2PKPMq-lDg=WB%L6Nk+=yC zBGFVH6Do$Mx)YwxM6#I0Q-R1flhr-_uyz{#HYsswZxt!r zkA{p2PUE_Bk2cddr{{2=mgtFhn5u|p&0h6bk(e!h!mwx;m_d8TXg|96D}_gM;vhV#3T1E($;&VW*AKV?_0NmEYeMWsh4*L$pF4|P7WvCr>X%07F(eUTvl zomuyKKq_fliNMhE%(JIm#h*o~PO01NXAL8=<2l!-ZA^ph?`M)E)rQrhJUtn|z;j&R ze>XVnCf&yU%KJH_pIc2Sy{FTycWfw%B<}OkGg+mItuioa%2+25)6=hsx>*D(7-bt! z-L1>mWLt_qhx*{VJOl;g&%$Iv+jZ^zWsP@gEmyJ zus-Mh25A@%$4ZRQSnzJ(RbH>?3gP+1C2q&u0R?ifiLP!gc(xn2)s|KDV(46vsbZtZ z@CSKrohQoF2MMM5S1oTlWnX7p=@O=GSzbjs^ux+i2;VMsv|UA8PtRwYDt6`J`Vf(> zfR{n104>n@IQTreQ99C5pHSqk!L3?<$CZyR1^Z7Mlc+FG`#qE0I0=N5SD$^cNROT9 zA0PyGDY>{A3cHKZp@i!9h0D%KLuh?fo=+9o58ts~E~OA)lOQ{Q=>Df0^V zPaLp%#sRedoC9vSXc0<+ksRQOyq9+DPj}%bgQS2{Od_`5K0|Z~02t=aQ5Zk|5rqzk zVm$oIGj_yh&)9vxDIJLtRD$xSxH0K0ZfyQ%apMh_A8})UH~>I}h4FBD%wS$KFNu$@ z1$dRN=?F5};q}xhr!{|39hJedWSPaFa_;tPZh8{TF@~wu6)~5RAy~?tKJ4h7D>0cu zLdHqN;r}7*5IT{?nPoa(&F8kn+q-$I&i`rqq(*hh*A`pm`uDmv(}ZR6u$q|rrFj$q zuNKwWv^wjc+Rdpo*28QS&#W5PbL0yiujEHYJ`L9^W9+rrQcIdO-Ap{Jhp7x`_$qyt$$4^dts;>P6uOFL`uRSCd0DqX z(4IFBcOJ=kz7^6hZE*dy8M9YQ*l2hr@Yb*c~c-028- zBB@>-`2ZI?0#A*M>XcjBJ{-9zavn_yS-0v5=*6(y7T=E!9@ev!N=UebMMMV10TB~B z!kDm&9oZzBi;F}DSFg6vTw|hmGe*UNb8XZXGJi6meSEp%B2CFRHvwFVunb%)6q%w1 z#@&EpU+FrobX;%w(q)eLC;UC04T4p@VvX}&y*o0xwhVO>o*D3u8v*b9dCN#|nLT}z z#%mVo`;_O4=7{dsG_Hm!_4PHVL8q{5fyX@k!lRaIaJR>SfAaNdm8`0{x^TUGn^7@S z@?b$$8hF)#xZ%4T!}5=_ya@#YIT0UjRbGP*wnse+nDd&z+Y4o(#Sqqh{2e2kQ(z#(>OrC@(}V`x;_)d5Iy@1rUwqr%{dhOZ}7Ts zPIN;lQYtDeVtlIFf~)>fyZy@fntpz!d00$&*pIv3;ZAdS#rcnko?zh9?zZO09#*`> z*4p0a52jGCx|#1?x)pw!&sitsx||acxf@ydBrdN$*2pg>|m-P60Q$Z5CT{;$S+}Fc->7};P zMvexWQnIXX`3!Xun5i$El{SHoNraS)cplMmcKJ&edva|t)ocYl3A+wK{Gm7SmF~q$)XF*rD@u0VVneCb$FgL zCbL%^gn%wutI8)naf{_(+!~W(%TQ+=>sifNy%|>g=3{+W7MJHx&&^<1V6Y2LaBd;@ zjtV@~FSGlT$;+av5&LD4d@&iSh1E2@UohA7+O50Yw(HdzyT?1;8V;KEm_00H6E$M) z^frC1*4ZCBex>}CF!vqej2JmyO3eEAtuBvaWe+O@FTBdJC|_F+MKKoP^-sA;agTGf zEB4WWZODE7d&^IDPbTu^s6K~047JM4r=Qvph( zb4x8_yfH=4o9#(OF-5y}Z?9@)ROilty@g<5;R7-+iHegk36$fSiU(U>N5;ZK%%1O~ zGGDo_8SD;1_rnXt3eh-rhjXy;{e1KINTzK5G{8-_@ zq;l_pQh3b#wfJZ6)1qJttS^!dx7`Rx%NNax16@k8Zyp*GRWj43D_&G}V&{)^+xfu8 zt6Q^(BH=HEkRHd+%#J@E1^P{1AB^?3#wjQLgK8YjeV4lua z4k4>CeY(v{aGg{kMuAl&;#4I@jb3JjnAS@S-b{n9!YhJr%XWW+T=pY1DkNf=X^E$gWt^kl zM-E&WNWhMajF4h_u&hV@K$s=NYFhA-ELwk9oJG2Av^(b~hbAW^+j;Ic_JFH6 z-Z&qkxw7bI?EI-)+2pe<BB|dDI4&ZfyG5sOxhk$@^ z`G_AYnWCDbo-x5lnyY6$WjCID*4L+zniJ1J)Wli*B%o%#7;|EZIfF z!?+tmhN=YQRE^r*V=2OI@$2hG1jc!-C5~5zDtD?0wdr_((icZR*L>h!DU z6)dJ$uUb`+jYtz?GHJBCzs^JNufExUccJ$tR`ZS56X>xNoyM5Ej@l_0dnTU>M|d9> z+EvEgL&4w839`Vq%phnUX^!fKKspMqRkCueJsQVS^=hROwh4L*oe}sVcqm$3;9j_# z-9{>Mm}TlZG-9j0e)xH0t9U=^RG$#@o5qNmTO}|XO>u=f2;>&GyyZe?-W815@+^9u z7RyV~DYaWnqx#f^MPOFbpCN43p?pBlw@Ip-}xZK!rg@>?4 z>WZBpcOOsZF*EmA+E|<-8S}x@KmMI~?JUZ^^3S8}=y_zOy>)sX*HwBIaZPWA?j+$el!q7dO`GsfC zrbuliUa+o~XSE-X4m5}*9!+mFVg%A-8j z8KIyP-cQV&L7g$mP~H+-3G0&g_U_kwt7KcbuX^zqiS8AAU6Od&YrXoKcSF_f5`ihK zp?&yarpeZF!fs}%&gII~@Dp6cMP z|Eo1bTf0HxT@&CIldhLO)pf7k-AYZSPcf?wYw0bQTJ17yPoiHf^cG5Dpn3X%f}W$7 zE^gGG+kQ>8pN}iCx<;7~l2SRs*X73bCV4!|$;k%U;q|M*maw&k}ZuW`jgEzE&p!vg| zs#W`y`U4vg=NJXSG;OB$fpuiFc3RYU&+ePJZJDua@N2xt^?g@%sfhi_huf~|%_{m< z_|F~iB}rfG6+h^b(GsLnCd{XfFsr5bgk2m}Y@?nUZ1zaPGJ+{kKK)gmPJCV==fOQj z=BeJYDWmsZEP6F$Sgfq}$t$*B%tU&gO+7E`wq`k{qY!!4=wHdX>Yf78k9?9E8!%uD z#k4i-iP2r?)PGo2-ap)+vv!Yd!v2AbdZSJLA&=$Jmh*}^(G9vwtC2Tl_|i6czv>D- zZv6Zjy0!*mZ>aLxHn`_@lPWl6o?;-*ew?$YNI*7s^6B%>RvXTltz&TM&7!M*)gdZu z2eoJ~uLzwc7PpYEeo(B!aQ~!ENVo1wInF6{F^ndGJwTuLm!o zB0(UMAiuYHoNcS7&>wU3wzFY9Mr*m5)1;F-(jlG7kgyw8l% zWy-xM_XRgC)&41pp+r2h@*coqdLP8;L#1!#pCu7ovcscERrtZ*7&@c+_@Ldy)c}5l zRZc^HrbP$Zjy_FH!>kl|?z;E@mMM!o2`qVcSEv$kYW!=JyA2IHt@N)x?3X{sRF zxvecFE+)_pd6SmkG#WFdYl7a9BowM}FFbP?#^#Wm|#*G~%A8{dd>auykxt&8b~$5*8Ws~Ruyj44!$%%p+p z-pjpk!zJ4~?Lldx%Co_chF7>8^wb0CX+3$df%y-NHzO?p>~XSDm9RM z7GFc3@YAXu+(4a#k~I8w)&M}AWDP5VTUpI zZkH(WP?0`eN~(aToLSemytIteAuyax?9HMprwYlHAu95C`G3gmP# zo&IB3vw0TQQ2q0;CeZ{L)~v*yhc#X}=zuz+f%@;HN=AP@d&Xbyr)T`HU6xB%|LYll zG+$p|Y~LUEuc5hl+Mm5(0SO)+hWQuxuWO2u$@Ivl{GqHrJ>`Ebtucb_5exc%|&GbCDo3eI0>zp4&KzO{@8bEp!D z^!+am>=K9B%m~CtcVe=)rm*w3mi<60Mxg!Y7unoIJJapOFS6tGZB*Z=xenj;4Q$LLo;O#s8lk%|_Um^ItaRMA-O$Z`l36b;Iue@J?$y z93u|Ia3F8dL;%Af4nMBXPY(X{63XIbq`R^W{^G7I5)T7Skgv>&_)Z2s*toz925`3j z+cLs%@n`CnefIAU5(8-OOjdlyYlu&C8fCou zUFsGw)s!-s2$u>Y#QKO+Cf@q&>n2oS6en{$VT`T_KF&_29Th`eo+79_eoJ9|xi@ZM zGc#FJQXC^pjHj>`*R)Ui`2rzXz~JKagZV(39K(cc&DHuLLwmu=>Gc=lJp7@f40C%c zizoVbgh)q@Z;X0RR!&nMta|!QGE0ShpllbPeOVuh=0)STEHT{@9$W49s9}>PFBXDM zf#uzuahZhQ%vT^&-#%KuglVn$^=sv4ea*^v(#gzZB8Q>y>-)a;p>Sa0~+4n>MHiJZh1{VCKmvh2&3H_}%Tw2M<4L z78jJ*%s#u!t8e5I<@~S|$GCFbLAdr|7hsXkhGxeijY_(w*h6coVHg#K5-mIWj?QB1 zS{iYGp|Th#F9UWp9hL9HoS250YSUf&wAvG1^XQ;VOn7i+upqUpoi zMn==Jhj*7{Hw2W{u^%;4DTW0QWT@9Z$!;U`y7jVCJS(y?pQVUXYcyjxHHM|ovl+KG zBA1JKrc#l~R$-C-VAqpJK_y?8UN-PXLPX+BqFj$bSKN%h%AA)NSBj7~M4PAWs`$c# zv^aO*AvF3~sFz5}(~|MGqidhGThav{Z_M|IKwd7fAJ=+k4=F&@i#WdU-nR9K<07|F zJ5{O`UjJse4hk(YpZjntwBhN1+X{X2^Je{#R9Ug?B#D!$YPMVX-$J=CwD}G$G|V1q ziw#^`k?bU~xuj<2h?hY+YeL>P%Omyo} zvB$h$voV#~F^#tEwQu{mjES6ke=NcAK|by-q~?LL?fii1sa`$yg?DViLrF13aqxMc ztyD)9{jg|#ngSo<+@yV61#u3YP| zsDIlg{+YY=RSExwlCtDp({%>U2Y5cYHY6XMD6b_x-&&n|3v!&fC}-yJc8i{i7IpMe z)t9Y67Bp_v`x{aRjAlvojq26D<1d7^PwBDd*|r?uk`GbHw{!2X6jss?z4^+k<6ZMI zvUcvn)|O%0kVizt`{z^?fG@XoaB$!jg_vAhd>Y#>b-GRi?M|j_$aQj@+;EVTYF^m^FoEGNX-j@mTu)VSr3~wbXWZm2Gcysrn zwdKde`|4WI3lt}tt*DW+mGaY+ZFCoJQ>tP#%8XiRW4dHiOD(g`W+cy}kv$5g!FR)~ zO%Z&A^TO<%+~*6GtewPMBe%G622^4&wKA?4QJb@TW_;jCVV*Bs{5d0*T4xVsacWn6AuyT9WOB4N>affOfRvQWM{N zQ?U~&#l$ms8+9+w=7d?7vE8qS`M!TB-KWrKV zI;-|K>~u&=??_PJP(m#k%^cC(H90Oe=4lx8e{9mGbUDOTwL|x-b|8CXt5^yb`DA;I zNmj&qgPFORE6z)t`-!@vkM_$1DW=Lg%(W098(Ho;MGhn7>mpB4*$EGdK4uwbC1y({ zVIua7#5E~YyNASN>J*HGpD8EaT)W%X##!Mr+kTl;0kqisCH=O-x~{CElqX|azg~BV zuq_{oX!6Fl0OwO_yV&rMNB-SUw}Xh^WE5z3E1%4O2<{81I_s_-jXt^vYuae4kVKQ- zPnOAv)_UKh zo6iBU;9WajixVLBo2Fl}>_e=j+g8))x0Q}tqq7e2bLFlfNvk~~d z^1I9B!T`k`5Md{Kz4o~>edIf%Z!Y6)PPfwoS__itj z%`!N+f{N}fuF^#$N;-v3kYsZSoYK=iDKi6S=_`=w`7ac3% z`-;q+^$Ra_6y{I)@T^EVnXC7Z0#!jb%LXMB(<9k1#WA*ObJS6eixzen)?Yg~VcSTa{>IWQ(*wP_1GIfq&m3S~w;rGRuy zZMsWvjkm;$2U3i4vEWr1jj5PCDT7v}hjk?rKi4Q3A;GtX9D<>bN^X*t1U0HrsIlB( zUn6Vy0ct_(QM{|w%zBgMcTFqyA76h&azKGG>G*IH$6c9^ z0&w{D*zc-+UEPNJZKX4SeH6LKJzYbOdTiswvv!u1k$ zu(&*|F)W+e&SEPJ>Z|-AU#$K8as9fJmf2mi3=V3v^|!GB;{n=tK6aLo)j&GFh2Lj1 zGg{=*&yVRZ^BNw4)oWo*W4h9KjU5GubFa6DQ6%A1sEJSvpgSdH-i*|`WUa-x$P;B$ z!uR#75x74olkkheNmHj2=O+r3{4$p`4gN-_>N~QB?koMf=Iwf#=k)J z$Lj{>*>$7p->)0RA;{~7dd>ND!=VHZU_%Ga_Fu0X=+wnukk<{SiJz|<#UW?c4GKz- zrWpWi6WS^Gzq_;ZIAo<97gP!MRA=7NnS|Cf8aOdv(rTcQlpH;{O zBkwr>y}zW+W_^Zvo9>paYhTq);Iv*)VJ5Mb)9k|9UVo8$Rt!c4ms|Z-rFh6Ihzaje zWw1UN^=tl8ZlkG;rpx#foKhjGp#;4X^0U zda>d9-ap}c%c`&Lmwa?z|AFV$$5~JM6Qu=Q(w9wt^I`M5$lp6OpG0+BR5<)j_oY`u z`?fgs+Lh%!E9AHTd=<)ZAV_dxOsegpvK6}+AMh!5Ri_D-*RSO(&)U0xtIuS+UeUX+ z{S@y%lzV-mwXE8k>(g9owsp((#LivKkgD~vn;vN|`>8SHhvTH|)Pw!bMuM9d-d^L& zKK`BUjfB1B#a&in{eIFp9FvUxu>YI3b zirs5ecCggMPfy@~Uob*mvcP)Ay*I<{Eor_j+&0K2^^8v|M{T%WawJ<*OT;qaNlxcyahxR#x%f zt8rN#)2eq%@A~hZwEoNA@)OISikTu3N!VwI(dP(GwpSH|=9-qve^F*N=TWOiL~;`gQJbbacE@%Ld(FA0?Fh_61LS z@y5DW<6`sO95>fDYL^yeoN98~IHRU@@_!$@*FV)&uYAo|^k?g(^BmvH_slrzVA1kGwptJ?&tMaPxtc1b4BgfW_y>u?)sai&$DMgeD!@| zvL>(geIMOV!JO?=_DXKtWBlw#;<`B=vu#9YC;SSD*s1x-S#_yg&fU_3BBFK+CL~O` zYrQTtxA5w`ruCn;&+oo&z~?=ed)*PcV+Xh2IG~{HmVEfQVO*(WmOyCHSFr}pGV6tA z%Z1pm&4TNWGuM3P{jATE^Dc5{=E@5>t)|@)?_a&y zzGn754~^R32~Re^?fzEwciDoyMG9_mye6Z{=@4u0D0wWCPjm;?kL#=F-2`6z7w-Mgu!lEj^>tVph=|x0zkKH zgP3ABmw|zi5rQ$!Vg1}80=`M54do`4`#v`Xnc7mJH>sQ?c$12wBZGpYlcTd+fLj3g zMipnE$^bVHAj=IT2D(axn447evD~Dh54}kRbgZ=l=1nR*3=4MiGWZ62`1`tohg=^g tF*7JIb1?`oG%zT9t4F(Ir34rtcOTcs$?MR=zX9u2t^xo6 literal 0 Hc-jL100001 diff --git a/tests/decode-teredo-01/test.yaml b/tests/decode-teredo-01/test.yaml new file mode 100644 index 000000000..53e2efdef --- /dev/null +++ b/tests/decode-teredo-01/test.yaml @@ -0,0 +1,567 @@ +requires: + min-version: 7 + +args: +- -k none + +checks: +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.id: 16995 + dns.rrname: ipv6.google.com + dns.rrtype: AAAA + dns.tx_id: 0 + dns.type: query + event_type: dns + pcap_cnt: 21 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.answers[0].rdata: ipv6.l.google.com + dns.answers[0].rrname: ipv6.google.com + dns.answers[0].rrtype: CNAME + dns.answers[0].ttl: 8655 + dns.answers[1].rdata: 2001:4860:0000:2001:0000:0000:0000:0068 + dns.answers[1].rrname: ipv6.l.google.com + dns.answers[1].rrtype: AAAA + dns.answers[1].ttl: 300 + dns.authorities[0].rdata: a.l.google.com + dns.authorities[0].rrname: l.google.com + dns.authorities[0].rrtype: NS + dns.authorities[0].ttl: 77923 + dns.authorities[1].rdata: b.l.google.com + dns.authorities[1].rrname: l.google.com + dns.authorities[1].rrtype: NS + dns.authorities[1].ttl: 77923 + dns.authorities[2].rdata: c.l.google.com + dns.authorities[2].rrname: l.google.com + dns.authorities[2].rrtype: NS + dns.authorities[2].ttl: 77923 + dns.authorities[3].rdata: d.l.google.com + dns.authorities[3].rrname: l.google.com + dns.authorities[3].rrtype: NS + dns.authorities[3].ttl: 77923 + dns.authorities[4].rdata: e.l.google.com + dns.authorities[4].rrname: l.google.com + dns.authorities[4].rrtype: NS + dns.authorities[4].ttl: 77923 + dns.authorities[5].rdata: f.l.google.com + dns.authorities[5].rrname: l.google.com + dns.authorities[5].rrtype: NS + dns.authorities[5].ttl: 77923 + dns.authorities[6].rdata: g.l.google.com + dns.authorities[6].rrname: l.google.com + dns.authorities[6].rrtype: NS + dns.authorities[6].ttl: 77923 + dns.flags: '8180' + dns.grouped.AAAA[0]: 2001:4860:0000:2001:0000:0000:0000:0068 + dns.grouped.CNAME[0]: ipv6.l.google.com + dns.id: 16995 + dns.qr: true + dns.ra: true + dns.rcode: NOERROR + dns.rd: true + dns.rrname: ipv6.google.com + dns.rrtype: AAAA + dns.type: answer + dns.version: 2 + event_type: dns + pcap_cnt: 22 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.id: 19995 + dns.rrname: ipv6.google.com + dns.rrtype: A + dns.tx_id: 2 + dns.type: query + event_type: dns + pcap_cnt: 23 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + app_proto: http + dest_ip: 75.126.203.78 + dest_port: 80 + event_type: fileinfo + fileinfo.filename: /cgi-bin/iavs4stats.cgi + fileinfo.gaps: false + fileinfo.size: 589 + fileinfo.state: CLOSED + fileinfo.stored: false + fileinfo.tx_id: 0 + http.hostname: download913.avast.com + http.http_method: POST + http.http_user_agent: Syncer/4.80 (av_pro-1169;f) + http.length: 0 + http.protocol: HTTP/1.0 + http.url: /cgi-bin/iavs4stats.cgi + pcap_cnt: 16 + proto: TCP + src_ip: 192.168.2.16 + src_port: 1578 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.answers[0].rdata: ipv6.l.google.com + dns.answers[0].rrname: ipv6.google.com + dns.answers[0].rrtype: CNAME + dns.answers[0].ttl: 8655 + dns.authorities[0].rrname: l.google.com + dns.authorities[0].rrtype: SOA + dns.authorities[0].soa.expire: 1800 + dns.authorities[0].soa.minimum: 60 + dns.authorities[0].soa.mname: c.l.google.com + dns.authorities[0].soa.refresh: 900 + dns.authorities[0].soa.retry: 900 + dns.authorities[0].soa.rname: dns-admin.google.com + dns.authorities[0].soa.serial: 1345503 + dns.authorities[0].ttl: 60 + dns.flags: '8180' + dns.grouped.CNAME[0]: ipv6.l.google.com + dns.id: 19995 + dns.qr: true + dns.ra: true + dns.rcode: NOERROR + dns.rd: true + dns.rrname: ipv6.google.com + dns.rrtype: A + dns.type: answer + dns.version: 2 + event_type: dns + pcap_cnt: 24 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.id: 38477 + dns.rrname: www.wireshark.org + dns.rrtype: AAAA + dns.tx_id: 4 + dns.type: query + event_type: dns + pcap_cnt: 58 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.aa: true + dns.flags: '8580' + dns.id: 38477 + dns.qr: true + dns.ra: true + dns.rcode: NOERROR + dns.rd: true + dns.rrname: www.wireshark.org + dns.rrtype: AAAA + dns.type: answer + dns.version: 2 + event_type: dns + pcap_cnt: 59 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 75.126.203.78 + dest_port: 80 + event_type: http + http.hostname: download913.avast.com + http.http_content_type: text/plain + http.http_method: POST + http.http_user_agent: Syncer/4.80 (av_pro-1169;f) + http.length: 0 + http.protocol: HTTP/1.0 + http.status: 204 + http.url: /cgi-bin/iavs4stats.cgi + pcap_cnt: 19 + proto: TCP + src_ip: 192.168.2.16 + src_port: 1578 + tx_id: 0 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.id: 26746 + dns.rrname: www.wireshark.org.gateway.2wire.net + dns.rrtype: AAAA + dns.tx_id: 6 + dns.type: query + event_type: dns + pcap_cnt: 60 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.aa: true + dns.flags: '8505' + dns.id: 26746 + dns.qr: true + dns.rcode: REFUSED + dns.rd: true + dns.rrname: www.wireshark.org.gateway.2wire.net + dns.rrtype: AAAA + dns.type: answer + dns.version: 2 + event_type: dns + pcap_cnt: 61 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.id: 34278 + dns.rrname: www.wireshark.org + dns.rrtype: A + dns.tx_id: 8 + dns.type: query + event_type: dns + pcap_cnt: 62 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.1 + dest_port: 53 + dns.aa: true + dns.answers[0].rdata: 67.228.110.120 + dns.answers[0].rrname: www.wireshark.org + dns.answers[0].rrtype: A + dns.answers[0].ttl: 14400 + dns.flags: '8580' + dns.grouped.A[0]: 67.228.110.120 + dns.id: 34278 + dns.qr: true + dns.ra: true + dns.rcode: NOERROR + dns.rd: true + dns.rrname: www.wireshark.org + dns.rrtype: A + dns.type: answer + dns.version: 2 + event_type: dns + pcap_cnt: 63 + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 67.228.110.120 + dest_port: 80 + event_type: http + http.hostname: www.wireshark.org + http.http_content_type: text/html + http.http_method: GET + http.http_refer: http://ipv6.google.com/search?hl=en&q=Wireshark+%21&btnG=Google+Search + http.http_user_agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9b5) + Gecko/2008032620 Firefox/3.0b5 + http.length: 3651 + http.protocol: HTTP/1.1 + http.status: 200 + http.url: / + pcap_cnt: 75 + proto: TCP + src_ip: 192.168.2.16 + src_port: 1580 + tx_id: 0 +- filter: + count: 1 + match: + app_proto: http + dest_ip: 192.168.2.16 + dest_port: 1580 + event_type: fileinfo + fileinfo.filename: / + fileinfo.gaps: false + fileinfo.size: 11845 + fileinfo.state: CLOSED + fileinfo.stored: false + fileinfo.tx_id: 0 + http.hostname: www.wireshark.org + http.http_content_type: text/html + http.http_method: GET + http.http_refer: http://ipv6.google.com/search?hl=en&q=Wireshark+%21&btnG=Google+Search + http.http_user_agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9b5) + Gecko/2008032620 Firefox/3.0b5 + http.length: 3651 + http.protocol: HTTP/1.1 + http.status: 200 + http.url: / + pcap_cnt: 75 + proto: TCP + src_ip: 67.228.110.120 + src_port: 80 +- filter: + count: 1 + match: + app_proto: failed + dest_ip: 192.168.2.16 + dest_port: 3797 + event_type: flow + flow.age: 0 + flow.alerted: false + flow.bytes_toclient: 0 + flow.bytes_toserver: 151 + flow.pkts_toclient: 0 + flow.pkts_toserver: 1 + flow.reason: shutdown + flow.state: new + proto: UDP + src_ip: 65.55.158.81 + src_port: 3544 +- filter: + count: 1 + match: + app_proto: dns + dest_ip: 192.168.2.1 + dest_port: 53 + event_type: flow + flow.age: 16 + flow.alerted: false + flow.bytes_toclient: 1246 + flow.bytes_toserver: 399 + flow.pkts_toclient: 5 + flow.pkts_toserver: 5 + flow.reason: shutdown + flow.state: established + proto: UDP + src_ip: 192.168.2.16 + src_port: 1920 +- filter: + count: 1 + match: + dest_ip: 192.168.2.16 + dest_port: 1576 + event_type: flow + flow.age: 27 + flow.alerted: false + flow.bytes_toclient: 108 + flow.bytes_toserver: 108 + flow.pkts_toclient: 2 + flow.pkts_toserver: 2 + flow.reason: shutdown + flow.state: new + proto: TCP + src_ip: 75.126.130.163 + src_port: 80 + tcp.tcp_flags: '00' + tcp.tcp_flags_tc: '00' + tcp.tcp_flags_ts: '00' +- filter: + count: 1 + match: + app_proto: failed + dest_ip: 192.168.2.255 + dest_port: 137 + event_type: flow + flow.age: 2 + flow.alerted: false + flow.bytes_toclient: 0 + flow.bytes_toserver: 276 + flow.pkts_toclient: 0 + flow.pkts_toserver: 3 + flow.reason: shutdown + flow.state: new + proto: UDP + src_ip: 192.168.2.16 + src_port: 137 +- filter: + count: 1 + match: + app_proto: failed + dest_ip: 192.168.2.255 + dest_port: 138 + event_type: flow + flow.age: 29 + flow.alerted: false + flow.bytes_toclient: 0 + flow.bytes_toserver: 500 + flow.pkts_toclient: 0 + flow.pkts_toserver: 2 + flow.reason: shutdown + flow.state: new + proto: UDP + src_ip: 192.168.2.16 + src_port: 138 +- filter: + count: 1 + match: + app_proto: dhcp + dest_ip: 255.255.255.255 + dest_port: 67 + event_type: flow + flow.age: 0 + flow.alerted: false + flow.bytes_toclient: 0 + flow.bytes_toserver: 342 + flow.pkts_toclient: 0 + flow.pkts_toserver: 1 + flow.reason: shutdown + flow.state: new + proto: UDP + src_ip: 0.0.0.0 + src_port: 68 +- filter: + count: 1 + match: + dest_ip: 2001:4860:0000:2001:0000:0000:0000:0068 + event_type: flow + flow.age: 0 + flow.alerted: false + flow.bytes_toclient: 0 + flow.bytes_toserver: 52 + flow.pkts_toclient: 0 + flow.pkts_toserver: 1 + flow.reason: shutdown + flow.state: new + icmp_code: 0 + icmp_type: 128 + proto: IPv6-ICMP + src_ip: 2001:0000:4137:9e50:8000:f12a:b9c8:2815 +- filter: + count: 1 + match: + dest_ip: 192.168.2.16 + dest_port: 1577 + event_type: flow + flow.age: 24 + flow.alerted: false + flow.bytes_toclient: 108 + flow.bytes_toserver: 162 + flow.pkts_toclient: 2 + flow.pkts_toserver: 3 + flow.reason: shutdown + flow.state: new + proto: TCP + src_ip: 75.126.203.78 + src_port: 80 + tcp.tcp_flags: '00' + tcp.tcp_flags_tc: '00' + tcp.tcp_flags_ts: '00' +- filter: + count: 1 + match: + app_proto: failed + dest_ip: 83.170.1.38 + dest_port: 32900 + event_type: flow + flow.age: 14 + flow.alerted: false + flow.bytes_toclient: 11789 + flow.bytes_toserver: 2863 + flow.pkts_toclient: 13 + flow.pkts_toserver: 12 + flow.reason: shutdown + flow.state: established + proto: UDP + src_ip: 192.168.2.16 + src_port: 3797 +- filter: + count: 1 + match: + app_proto: http + dest_ip: 75.126.203.78 + dest_port: 80 + event_type: flow + flow.age: 19 + flow.alerted: false + flow.bytes_toclient: 445 + flow.bytes_toserver: 1122 + flow.pkts_toclient: 5 + flow.pkts_toserver: 6 + flow.reason: shutdown + flow.state: closed + proto: TCP + src_ip: 192.168.2.16 + src_port: 1578 + tcp.ack: true + tcp.psh: true + tcp.rst: true + tcp.state: closed + tcp.syn: true + tcp.tcp_flags: 1e + tcp.tcp_flags_tc: 1e + tcp.tcp_flags_ts: 1e +- filter: + count: 1 + match: + app_proto: failed + dest_ip: 65.55.158.80 + dest_port: 3544 + event_type: flow + flow.age: 9 + flow.alerted: false + flow.bytes_toclient: 90 + flow.bytes_toserver: 213 + flow.pkts_toclient: 1 + flow.pkts_toserver: 2 + flow.reason: shutdown + flow.state: established + proto: UDP + src_ip: 192.168.2.16 + src_port: 3797 +- filter: + count: 1 + match: + app_proto: http + dest_ip: 67.228.110.120 + dest_port: 80 + event_type: flow + flow.age: 1 + flow.alerted: false + flow.bytes_toclient: 4248 + flow.bytes_toserver: 855 + flow.pkts_toclient: 6 + flow.pkts_toserver: 7 + flow.reason: shutdown + flow.state: closed + proto: TCP + src_ip: 192.168.2.16 + src_port: 1580 + tcp.ack: true + tcp.fin: true + tcp.psh: true + tcp.state: closed + tcp.syn: true + tcp.tcp_flags: 1b + tcp.tcp_flags_tc: 1b + tcp.tcp_flags_ts: 1b -- 2.47.2