Actions
Feature #5446
closedallow ranges in dns.opcode value
Effort:
Difficulty:
Label:
Description
It would be nice to be able to write a single rule looking for a range of opcodes or not looking (excluding) a range of opcodes.
examples:
alert dns any any -> any any (msg:"dns unassigned opcodes in dns query"; dns.opcode:7-15; sid:123; rev:1;)
alert dns any any -> any any (msg:"dns opcode other than assigned opcode in dns query"; dns.opcode:!1-6; sid:123; rev:1;)
Updated by Victor Julien over 2 years ago
@Philippe Antoine could this somehow be implemented as part of the general detect int work?
Updated by Philippe Antoine over 1 year ago
- Assignee changed from OISF Dev to Philippe Antoine
Updated by Philippe Antoine over 1 year ago
- Target version changed from TBD to 8.0.0-beta1
Updated by Philippe Antoine 12 months ago
- Status changed from New to In Review
Updated by Philippe Antoine 10 months ago
- Related to Feature #6646: detect: integer: support negated ranges added
Updated by Philippe Antoine 10 months ago
- Related to Task #6644: tracking: detect: integer as first-class support added
Updated by Philippe Antoine 10 months ago
- Related to Feature #6723: detect: review existing keywords for usage of enumerations added
Updated by Philippe Antoine 10 months ago
- Status changed from In Review to Closed
Actions