Actions
Feature #2758
closedintel / reputation matching on arbitrary data
Effort:
Difficulty:
Label:
Description
Implement a way for the engine to match on arbitrary data for checking it against intel / reputation. Rule lang would drive this. I see this as a mix between #2318 and more advanced transformation support.
Updated by Victor Julien about 6 years ago
- Related to Task #2685: SuriCon 2018 brainstorm added
Updated by Victor Julien over 5 years ago
- Status changed from Assigned to Closed
- Target version changed from TBD to 5.0rc1
- Effort deleted (
high) - Difficulty deleted (
high)
Actions