Project

General

Profile

Actions

Feature #7533

open

detect: add ldap.request.attribute_type and ldap.request.attribute keywords, and same for responses

Added by Alice da Silva Akaki 5 days ago. Updated 2 days ago.

Status:
New
Priority:
High
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Add keywords to match on AttributeType and AttributeValue

Eve fields to match:
ldap.request.search_request.attributes[]
ldap.request.modify_request.changes[].modification.attribute_type
ldap.request.add_request.attributes[].name
ldap.request.compare_request.attribute_value_assertion.description
ldap.responses[].search_result_entry.attributes[].type

ldap.request.modify_request.changes[].modification.attribute_values[]
ldap.request.add_request.attributes[].values[]
ldap.responses[].search_result_entry.attributes[].values[]
ldap.request.compare_request.attribute_value_assertion.value


Related issues 1 (1 open0 closed)

Blocks Suricata - Task #7452: ldap: add keywords to match outputNewAlice da Silva AkakiActions
Actions #1

Updated by Philippe Antoine 3 days ago

  • Subject changed from detect: add ldap.request.attribute and ldap.responses.attribute keywords to detect: add ldap.request.attribute_type and ldap.request.attribute keywords, and same for responses
Actions #2

Updated by Philippe Antoine 3 days ago

  • Blocks Task #7452: ldap: add keywords to match output added
Actions #3

Updated by Alice da Silva Akaki 2 days ago

  • Description updated (diff)
Actions

Also available in: Atom PDF