Actions
Feature #7095
open
PM
OD
rdp: keywords additions
Feature #7095:
rdp: keywords additions
Description
While Suricata generates RDP protocol logs itself , it is often useful to have rdp keywords available so custom signatures can be developed.
Currently we have none.
- rdp client version
- rdp client name
- rdp client cookie
- rdp cleint build
- rdp client keyboard type
- rdp x509 serial
The screenshot attached are Kibana visualizations from the regular protocol log (event_type rdp) produced by Suricata
Files
JI Updated by Jason Ish almost 2 years ago
- Related to Story #6597: rules: improve rules keyword/output parity added
PA Updated by Philippe Antoine almost 2 years ago
- Related to Optimization #3304: generic way to register buffers for logging and detection added
LS Updated by Lukas Sismis almost 2 years ago
- Related to Feature #7100: smb: additional keywords added
LS Updated by Lukas Sismis almost 2 years ago
- Related to deleted (Feature #7100: smb: additional keywords)
VJ Updated by Victor Julien almost 2 years ago
- Subject changed from rdp keywords additions to rdp: keywords additions
Actions