--- /dev/null
+alert tcp any any -> any any (msg:"DCERPC stub data match"; dce_stub_data; content:"|42 42 42 42|"; sid:1;)
--- /dev/null
+args:
+- -k none --set stream.inline=true
+
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ pcap_cnt: 8
--- /dev/null
+alert tcp any any -> any any (msg:"DCERPC stub data match"; dce_stub_data; content:"|42 42 42 42|"; sid:1;)
--- /dev/null
+args:
+- -k none --set stream.inline=true
+
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ pcap_cnt: 4
\ No newline at end of file
--- /dev/null
+alert tcp any any -> any any (msg:"DCERPC stub data request1"; dce_stub_data; content:"|00 02|"; sid:1;)
+alert tcp any any -> any any (msg:"DCERPC stub data request2"; dce_stub_data; content:"|00 75|"; sid:2;)
+alert tcp any any -> any any (msg:"DCERPC stub data request3"; dce_stub_data; content:"|00 18|"; sid:3;)
--- /dev/null
+args:
+- -k none --set stream.inline=true
+
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ pcap_cnt: 8
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+ pcap_cnt: 12
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 3
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 3
+ pcap_cnt: 16
--- /dev/null
+alert tcp any any -> any any (msg:"DCERPC stub data request1"; dce_stub_data; content:"|00 02|"; sid:1;)
+alert tcp any any -> any any (msg:"DCERPC stub data request2"; dce_stub_data; content:"|00 75|"; sid:2;)
+alert tcp any any -> any any (msg:"DCERPC stub data request3"; dce_stub_data; content:"|00 18|"; sid:3;)
--- /dev/null
+args:
+- -k none --set stream.inline=true
+
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ pcap_cnt: 4
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+ pcap_cnt: 8
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 3
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 3
+ pcap_cnt: 12
--- /dev/null
+alert dns any any -> any any (dce_stub_data; content:"0"; sid:1;)
--- /dev/null
+args:
+- --init-errors-fatal
+
+pcap: false
+
+exit-code: 1