Project

General

Profile

Actions

Feature #2198

closed

Extend the DNS parser to accept dns_response keyword in signatures

Added by Anonymous over 7 years ago. Updated 2 days ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

For A and AAAA records it would be interesting to match on the IP received from the DNS resolver.
In particular this could be useful to check for potentially sink-holed domains.


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #2448: Add additional buffers for DNS ResponsesNewJason IshActions
Is duplicate of Suricata - Feature #7012: rules: add dns.response sticky bufferClosedNathan ScrivensActions
Actions

Also available in: Atom PDF