Project

General

Profile

Actions

Feature #7508

open

rules: ftp.reply keyword

Added by Victor Julien 2 months ago. Updated about 18 hours ago.

Status:
In Review
Priority:
High
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Match on the tracked replies (eve's ftp.reply). Since there can be more than 1, it's probably a multi-buffer.


Related issues 2 (2 open0 closed)

Blocks Suricata - Task #6476: ftp: parity of logging and detection buffersIn ProgressJeff LucovskyActions
Copied from Suricata - Feature #7507: rules: ftp.completion_code keywordNewJeff LucovskyActions
Actions #1

Updated by Victor Julien 2 months ago

  • Copied from Feature #7507: rules: ftp.completion_code keyword added
Actions #2

Updated by Victor Julien 2 months ago

  • Blocks Task #6476: ftp: parity of logging and detection buffers added
Actions #3

Updated by Victor Julien about 1 month ago

  • Priority changed from Normal to High
Actions #4

Updated by Jeff Lucovsky about 18 hours ago

  • Status changed from New to In Review
Actions

Also available in: Atom PDF