Project

General

Profile

Actions

Feature #1320

closed

packet content in alert msg

Added by god lol over 9 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

It would be handy if there would be a way to include part of the packet content (pcre match or n bytes at offset x) into "msg" part of the alert.

This would make extracting data from various protocols not supported explicitly much easier. For example extraction of sip caller and callee would be as easy as http url extraction now.

Actions

Also available in: Atom PDF