Actions
Feature #7103
openssh: extra fields and keywords
Description
Consider adding more ssh protocol fields (to the existing ssh protocol logging) and ssh keywords (to the rules for matching) to be able to match on such cases as described in the blog here:
https://corelight.com/blog/newsroom/news/zeek-metadata-ssh-terrapin
- Message authentication
- Encryption
- Key Exchange
- Compression
This is good both for detection and audit of networks traffic
Updated by Victor Julien 6 months ago
- Subject changed from ssh extra fields and keywords to ssh: extra fields and keywords
Updated by Victor Julien 6 months ago
- Related to Feature #4148: Research: SSH Support for additional protocol analysis added
Updated by Victor Julien 6 months ago
- Related to Feature #5734: ssh: add frame support added
Updated by Lukas Sismis 6 months ago
- Status changed from New to Feedback
More info is needed what is required, is it the textual representation of the individual fields?
Actions