checks:
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
id: 1
lists.packet.matches[0].name: "icmp_id"
- lists.packet.matches[0].id.number: 2
\ No newline at end of file
+ lists.packet.matches[0].id.number: 2
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 1
+ lists.packet.matches[0].name: "icmp_id"
+ lists.packet.matches[0].id.equal: 2
\ No newline at end of file
checks:
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
lists.packet.matches[0].name: "tcp.seq"
lists.packet.matches[0].seq.number: 624
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
id: 2
- lists.packet.matches[0].seq.number: 723833
\ No newline at end of file
+ lists.packet.matches[0].seq.number: 723833
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 1
+ lists.packet.matches[0].name: "tcp.seq"
+ lists.packet.matches[0].seq.equal: 624
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 2
+ lists.packet.matches[0].seq.equal: 723833
\ No newline at end of file
checks:
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
lists.packet.matches[0].name: "tcp.ack"
lists.packet.matches[0].ack.number: 782
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
id: 2
lists.packet.matches[0].ack.number: 15
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
id: 3
lists.packet.matches[0].name: "tcp.ack"
- lists.packet.matches[0].ack.number: 437528
\ No newline at end of file
+ lists.packet.matches[0].ack.number: 437528
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 1
+ lists.packet.matches[0].name: "tcp.ack"
+ lists.packet.matches[0].ack.equal: 782
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 2
+ lists.packet.matches[0].ack.equal: 15
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 3
+ lists.packet.matches[0].name: "tcp.ack"
+ lists.packet.matches[0].ack.equal: 437528
\ No newline at end of file
checks:
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
lists.packet.matches[0].name: "tcp.window"
lists.packet.matches[0].window.size: 30336
lists.packet.matches[0].window.negated: false
-
- filter:
+ lt-version: 9.0
filename: rules.json
count: 1
match:
id: 2
lists.packet.matches[0].name: "tcp.window"
lists.packet.matches[0].window.size: 1024
- lists.packet.matches[0].window.negated: true
\ No newline at end of file
+ lists.packet.matches[0].window.negated: true
+
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 1
+ lists.packet.matches[0].name: "tcp.window"
+ lists.packet.matches[0].window.equal: 30336
+- filter:
+ min-version: 9.0
+ filename: rules.json
+ count: 1
+ match:
+ id: 2
+ lists.packet.matches[0].name: "tcp.window"
+ lists.packet.matches[0].window.diff: 1024
\ No newline at end of file