Project

General

Profile

Actions

Feature #7594

open
JF OD

Feature #7600: mime: add rule keywords

mime: add email.status keyword

Feature #7594: mime: add email.status keyword

Added by Juliana Fajardini Reichow about 1 year ago. Updated about 1 year ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Related issues 11 (1 open10 closed)

Related to Suricata - Feature #7587: mime: add email.body_md5 keywordClosedAlice da Silva AkakiActions
Related to Suricata - Feature #7588: mime: add email.cc keywordClosedAlice da Silva AkakiActions
Related to Suricata - Task #7591: mime: add email.date keywordClosedAlice da Silva AkakiActions
Related to Suricata - Feature #7592: mime: add email.from keywordClosedAlice da Silva AkakiActions
Related to Suricata - Feature #7593: mime: add email.message_id keywordClosedAlice da Silva AkakiActions
Related to Suricata - Feature #7595: mime: add email.subject keywordClosedAlice da Silva AkakiActions
Related to Suricata - Feature #7596: mime: add email.to keywordClosedAlice da Silva AkakiActions
Related to Suricata - Feature #7597: mime: add email.url keywordClosedAlice da Silva AkakiActions
Related to Suricata - Task #7598: mime: add email.x_mailerClosedAlice da Silva AkakiActions
Related to Suricata - Documentation #7683: mime: add email.attachment keywordClosedAlice da Silva AkakiActions
Blocks Suricata - Story #7901: 9.0.0: rules: improve rules keyword/output parityAssignedVictor JulienActions

JF Updated by Juliana Fajardini Reichow about 1 year ago Actions #1

  • Blocks Story #6597: rules: improve rules keyword/output parity added

JF Updated by Juliana Fajardini Reichow about 1 year ago Actions #2

  • Related to Feature #7587: mime: add email.body_md5 keyword added
  • Related to Feature #7588: mime: add email.cc keyword added
  • Related to Task #7591: mime: add email.date keyword added
  • Related to Feature #7592: mime: add email.from keyword added
  • Related to Feature #7593: mime: add email.message_id keyword added

JF Updated by Juliana Fajardini Reichow about 1 year ago Actions #3

  • Related to Feature #7595: mime: add email.subject keyword added

JF Updated by Juliana Fajardini Reichow about 1 year ago Actions #4

JF Updated by Juliana Fajardini Reichow about 1 year ago Actions #5

JF Updated by Juliana Fajardini Reichow about 1 year ago Actions #6

  • Related to Task #7598: mime: add email.x_mailer added

JF Updated by Juliana Fajardini Reichow about 1 year ago Actions #7

  • Parent task set to #7600

VJ Updated by Victor Julien about 1 year ago Actions #8

  • Tracker changed from Task to Feature

AD Updated by Alice da Silva Akaki about 1 year ago Actions #9

  • Status changed from New to In Progress
  • Assignee changed from OISF Dev to Alice da Silva Akaki

VJ Updated by Victor Julien about 1 year ago Actions #10

  • Status changed from In Progress to New
  • Assignee changed from Alice da Silva Akaki to OISF Dev
  • Target version changed from 8.0.0-rc1 to TBD

It looks like we can't do much here, as in master we always log "status" and "PARSE_DONE". In 7.0.x we could also log "PARSE_ERROR". Lets stop this for now and revisit later if there is something meaningful to do here.

AD Updated by Alice da Silva Akaki 12 months ago Actions #11

VJ Updated by Victor Julien 7 months ago Actions #12

  • Blocks deleted (Story #6597: rules: improve rules keyword/output parity)

VJ Updated by Victor Julien 7 months ago Actions #13

  • Blocks Story #7901: 9.0.0: rules: improve rules keyword/output parity added
Actions

Also available in: PDF Atom