Actions
Feature #5446
openallow ranges in dns.opcode value
Effort:
Difficulty:
Label:
Description
It would be nice to be able to write a single rule looking for a range of opcodes or not looking (excluding) a range of opcodes.
examples:
alert dns any any -> any any (msg:"dns unassigned opcodes in dns query"; dns.opcode:7-15; sid:123; rev:1;)
alert dns any any -> any any (msg:"dns opcode other than assigned opcode in dns query"; dns.opcode:!1-6; sid:123; rev:1;)
Updated by Victor Julien over 1 year ago
@Philippe Antoine could this somehow be implemented as part of the general detect int work?
Updated by Philippe Antoine 6 months ago
- Assignee changed from OISF Dev to Philippe Antoine
Updated by Philippe Antoine 6 months ago
- Target version changed from TBD to 8.0.0-beta1
Updated by Philippe Antoine 3 days ago
- Status changed from New to In Review
Actions