Actions
Feature #7481
openrules/actions: explicit action scopes
Effort:
Difficulty:
Label:
Description
Allow setting the scope of the applied action (packet or flow currently) explicitly in the rule.
Suggesting a syntax:
(drop|pass)[:(packet|flow)] pass:flow tls any any -> any any (tls.sni; content:"suricata.io"; ... )
Updated by Victor Julien 12 days ago
- Target version changed from TBD to 8.0.0-beta1
Updated by Victor Julien 12 days ago
- Blocks Story #7164: usecase: improve firewall usecase added
Actions