Project

General

Profile

Actions

Task #7452

open

ldap: add keywords to match output

Added by Philippe Antoine about 2 months ago. Updated 2 days ago.

Status:
New
Priority:
High
Target version:
Effort:
Difficulty:
Label:

Subtasks 3 (3 open0 closed)

Feature #7453: ldap: add ldap.request.operation and ldap.response.operation keywordsIn ReviewAlice da Silva AkakiActions
Feature #7470: detect: add ldap.bind.version keywordNewAlice da Silva AkakiActions
Feature #7471: detect/ldap: add ldap.distinguished_name keywordNewAlice da Silva AkakiActions

Related issues 3 (1 open2 closed)

Related to Suricata - Feature #1199: protocol: LDAP supportClosedGiuseppe LongoActions
Related to Suricata - Feature #7477: ldap: add support for AbandonRequestClosedAlice da Silva AkakiActions
Blocks Suricata - Story #6597: rules: improve rules keyword/output parityNewVictor JulienActions
Actions #1

Updated by Philippe Antoine about 2 months ago

  • Blocks Story #6597: rules: improve rules keyword/output parity added
Actions #2

Updated by Philippe Antoine about 2 months ago

  • Tracker changed from Feature to Task
Actions #3

Updated by Juliana Fajardini Reichow about 2 months ago

Actions #4

Updated by Philippe Antoine about 2 months ago

  • Subtask #7453 added
Actions #5

Updated by Philippe Antoine about 1 month ago

  • Subtask #7470 added
Actions #6

Updated by Philippe Antoine about 1 month ago

  • Subtask #7471 added
Actions #7

Updated by Alice da Silva Akaki 19 days ago

  • Related to Feature #7477: ldap: add support for AbandonRequest added
Actions #8

Updated by Philippe Antoine 2 days ago

List of keywords to add :
- ldap.dn : buffer , maps to bind_request.name, search_request.base_object, etc... # comment if there is something to say
- ldap.result.code : integer

First, the generic keywords that work for multiple operations, based on the LDAP ASN1 definition

And then the remaining fields in json schema like bind_request.version, ordered by priority

Actions

Also available in: Atom PDF