]> git.ipfire.org Git - thirdparty/suricata.git/commit
detect: add email.message_id keyword
authorAlice Akaki <akakialice@gmail.com>
Tue, 1 Apr 2025 19:40:25 +0000 (15:40 -0400)
committerVictor Julien <victor@inliniac.net>
Thu, 3 Apr 2025 08:05:48 +0000 (10:05 +0200)
commit52e12410ed4af489aa52c16c025b80ad05b66d42
tree2e1e5f27adadf7919d3843cb96c6221fc62e4d32
parent2dfd2a752f7e0429f0a1696da76cb4a0ae5aa9f6
detect: add email.message_id keyword

email.message_id matches on MIME EMAIL Message-Id
This keyword maps to the EVE field email.message_id
It is a sticky buffer
Supports prefiltering

Ticket: #7593
doc/userguide/rules/email-keywords.rst
src/detect-email.c