Actions
Feature #7095
openrdp: keywords additions
Description
While Suricata generates RDP protocol logs itself , it is often useful to have rdp keywords available so custom signatures can be developed.
Currently we have none.
- rdp client version
- rdp client name
- rdp client cookie
- rdp cleint build
- rdp client keyboard type
- rdp x509 serial
The screenshot attached are Kibana visualizations from the regular protocol log (event_type rdp) produced by Suricata
Files
Actions