Project

General

Profile

Actions

Feature #776

open

Task #6473: detect: smtp keyword coverage

rules: Add smtp_envelope and smtp_header keywords

Added by David André over 11 years ago. Updated about 1 year ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Beginner

Description

Add smtp_envelope and smtp_header keywords.

The envelope is composed of communication before the DATA segment ( example at http://en.wikipedia.org/wiki/SMTP#SMTP_transport_example) and the header is the part of the email content before there is the mail body (which should be anything between DATA and the first occurence of CR LF CR LF).

The idea is to allow rules searching for email addresses, mail user-agents, etc.. while not matching on the same pattern(s) being discussed in an email body.


Related issues 3 (2 open1 closed)

Related to Suricata - Task #4097: Suricon 2020 brainstormAssignedVictor JulienActions
Related to Suricata - Feature #6198: Feature Request: Add "SMTP" keywords for use in rulesNewOISF DevActions
Related to Suricata - Feature #3487: mime: multi-part parser in RustClosedPhilippe AntoineActions
Actions

Also available in: Atom PDF