Project

General

Profile

Actions

Feature #6198

open
AD OD

smtp: add keywords for use in rules

Feature #6198: smtp: add keywords for use in rules

Added by Andreas Dolp almost 3 years ago. Updated over 1 year ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Suricata has an app-layer parser / protocol support for SMTP builtin since long time ago, but no keywords are available for use in rules.

This feature request wants to add SMTP keyword support to Suricata, so that these keywords can be used in rules.

To focus development, this ticket also tries to collect some helpful use cases for such SMTP keywords:
  • MAIL FROM: <address> and RCPT TO: <address> compatible to use in datasets, e.g. e-mail blacklist
  • HELO / EHLO: <server> -> dataset blacklist
  • AUTH to detect multiple login attempts
  • Return-Codes
  • Other headers (Subject, Content-Type) in the DATA part, ideally with custom header support

Feel free to add further use cases.

Thanks!


Related issues 5 (4 open1 closed)

Related to Suricata - Feature #776: rules: Add smtp_envelope and smtp_header keywordsAssignedOISF DevActions
Related to Suricata - Task #6473: tracking: detect: smtp keyword coverageAssignedVictor JulienActions
Related to Suricata - Task #6443: Suricon 2023 brainstormAssignedVictor JulienActions
Related to Suricata - Story #6597: rules: improve rules keyword/output parityClosedVictor JulienActions
Related to Suricata - Feature #6474: detect: smtp body inspection keywordNewOISF DevActions

VJ Updated by Victor Julien almost 3 years ago Actions #1

  • Related to Feature #776: rules: Add smtp_envelope and smtp_header keywords added

VJ Updated by Victor Julien over 2 years ago Actions #2

  • Related to Task #6473: tracking: detect: smtp keyword coverage added

VJ Updated by Victor Julien over 2 years ago Actions #3

  • Related to Task #6443: Suricon 2023 brainstorm added

JF Updated by Juliana Fajardini Reichow over 1 year ago Actions #4

  • Related to Story #6597: rules: improve rules keyword/output parity added

VJ Updated by Victor Julien over 1 year ago Actions #5

  • Subject changed from Feature Request: Add "SMTP" keywords for use in rules to smtp: add keywords for use in rules

PA Updated by Philippe Antoine over 1 year ago Actions #6

  • Related to Feature #6474: detect: smtp body inspection keyword added
Actions

Also available in: PDF Atom