Project

General

Profile

Actions

Feature #2075

closed

Wildcard matching in suricata hex content matching

Added by Jason Williams about 7 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
-
Effort:
Difficulty:
Label:

Description

There could be use cases where being able to use wildcards in hex content would be useful, replacing the need for pcre.

example:

content:"watch me count|3a 20 00 01 02 ?? 04|";

Actions

Also available in: Atom PDF