Negated content with distance FP
The following signature:
alert udp any any -> any any (msg:"Negated content with distance test"; content:"|C0 0C 00 10 00 01|"; content:!"v=spf"; distance:0; sid:30303; rev:1;)
This rule alerts on the attached pcap. The attached pcap has 'v=spf' in the packet after the hex content in the signature.
Tested with 6.0.0-dev (e5fd47dcf 2020-05-01), 5.0.3, 4.1.8, 4.0.7.