Project

General

Profile

Actions

Feature #1100

closed

keyword: file_ext keyword

Added by Victor Julien almost 11 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

Like fileext, match on file extensions, but act like file_data.

file_ext; content:"exe"; nocase;

Complication is that fileext really just looks at the file name, and checks if the last bytes of it are what the fileext keyword contains, preceded by a dot. Might not be as easy to convert.


Related issues 1 (0 open1 closed)

Related to Suricata - Feature #1099: keyword: file_name keywordClosedVictor JulienActions
Actions

Also available in: Atom PDF