Project

General

Profile

Actions

Documentation #5484

open

userguide: explain content modifiers usage with regards to position usage in the rule

Added by Juliana Fajardini Reichow over 2 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Some content modifier keywords may not present the expected behavior if they are not used in the position Suri expects them to be.

This needs some investigation to decide which keywords present that and would need a better explanation, but an example can likely be seen in bug 4286.


Related issues 2 (2 open0 closed)

Related to Suricata - Bug #4286: FN occurs when using negated isdataat with http_cookie keywordFeedbackCommunity TicketActions
Related to Suricata - Task #5483: SV tests to demonstrate false negative behavior for negated isdataat with http_cookie keyword (bug 4286)NewOISF DevActions
Actions

Also available in: Atom PDF