Project

General

Profile

Feature #2758

intel / reputation matching on arbitrary data

Added by Victor Julien 3 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
high
Difficulty:
high
Label:

Description

Implement a way for the engine to match on arbitrary data for checking it against intel / reputation. Rule lang would drive this. I see this as a mix between #2318 and more advanced transformation support.


Related issues

Related to Support #2685: SuriCon 2018 brainstormNewActions

History

#1

Updated by Victor Julien 3 months ago

Also available in: Atom PDF