Project

General

Profile

Actions

Feature #5705

open

protocol: Wireguard parser

Added by Odin Jenseg about 3 years ago. Updated 14 days ago.

Status:
Assigned
Priority:
Normal
Target version:
Effort:
medium
Difficulty:
Label:
Protocol

Description

Adding a parser for the Wireguard VPN protocol.

  • Includes detection of the protocol using patterns.
  • Protocol logs

PR should be available before end of this year.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #8123: Suricon 2025 BrainstormAssignedVictor JulienActions
Actions #1

Updated by Victor Julien about 3 years ago

  • Status changed from New to In Progress
Actions #2

Updated by Juliana Fajardini Reichow 16 days ago

  • Related to Task #8123: Suricon 2025 Brainstorm added
Actions #3

Updated by Juliana Fajardini Reichow 16 days ago

Pierre Chifflier indicates he has a Wireguard parser.

Actions #4

Updated by Victor Julien 14 days ago

  • Status changed from In Progress to Assigned
  • Assignee changed from Odin Jenseg to Pierre Chifflier

@Pierre Chifflier did you have that parser in your public rust crates or somewhere else?

In general we discussed at suricon 2025 that protocol detection is probably the most interesting part.

Actions #5

Updated by Victor Julien 14 days ago

  • Subject changed from Add Wireguard parser to protocol: Wireguard parser
Actions

Also available in: Atom PDF