Project

General

Profile

Actions

Feature #741

closed

Introduce endswith keyword

Added by Anoop Saldanha about 11 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

endswith is a modifier to the existing content keyword. It matches if the content string matches at the end of the buffer being matched. Usage wise it works the same as nocase.

Should we allow depth and within to be used with endswith keyword?


Related issues 2 (1 open1 closed)

Related to Suricata - Task #2309: SuriCon 2017 brainstormAssignedVictor JulienActions
Related to Suricata - Feature #742: startswith keywordClosedVictor Julien02/01/2013Actions
Actions

Also available in: Atom PDF