Project

General

Profile

Actions

Feature #7095

open

rdp: keywords additions

Added by Peter Manev 3 months ago. Updated 3 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

While Suricata generates RDP protocol logs itself , it is often useful to have rdp keywords available so custom signatures can be developed.
Currently we have none.

Interesting use cases can be for keywords , that we already have logging for, can be:
  • rdp client version
  • rdp client name
  • rdp client cookie
  • rdp cleint build
  • rdp client keyboard type
  • rdp x509 serial

The screenshot attached are Kibana visualizations from the regular protocol log (event_type rdp) produced by Suricata


Files


Related issues 2 (2 open0 closed)

Related to Suricata - Story #6597: rules: impove rules keyword/output parityNewVictor JulienActions
Related to Suricata - Optimization #3304: generic way to register buffers for logging and detectionNewOISF DevActions
Actions #1

Updated by Jason Ish 3 months ago

  • Related to Story #6597: rules: impove rules keyword/output parity added
Actions #2

Updated by Philippe Antoine 3 months ago

  • Related to Optimization #3304: generic way to register buffers for logging and detection added
Actions #3

Updated by Lukas Sismis 3 months ago

Actions #4

Updated by Lukas Sismis 3 months ago

Actions #5

Updated by Victor Julien 3 months ago

  • Subject changed from rdp keywords additions to rdp: keywords additions
Actions

Also available in: Atom PDF