Project

General

Profile

Actions

Feature #2758

closed

intel / reputation matching on arbitrary data

Added by Victor Julien about 6 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Implement a way for the engine to match on arbitrary data for checking it against intel / reputation. Rule lang would drive this. I see this as a mix between #2318 and more advanced transformation support.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #2685: SuriCon 2018 brainstormAssignedVictor JulienActions
Actions #1

Updated by Victor Julien about 6 years ago

  • Related to Task #2685: SuriCon 2018 brainstorm added
Actions #2

Updated by Victor Julien over 5 years ago

  • Status changed from Assigned to Closed
  • Target version changed from TBD to 5.0rc1
  • Effort deleted (high)
  • Difficulty deleted (high)
Actions

Also available in: Atom PDF