Project

General

Profile

Actions

Feature #5639

closed

datasets: allow matching on extracted domain

Added by Eric Leblond about 3 years ago. Updated 6 days ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

When matching on tls.sni or http.host, it is convenient to match on the domain name inside the value instead of matching on the full value. If endswith can be used for one domain in one signature using dataset would be more useful.


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #5681: datasets: add more transform layers to match on domainsFeedbackCommunity TicketActions
Related to Suricata - Feature #6802: Support Domain rollup using existing dataset libraryFeedbackOISF DevActions
Actions

Also available in: Atom PDF