General

Profile

PA Philippe Antoine

  • Login: catenacyber
  • Registered on: 01/25/2018
  • Last sign in: 04/28/2026

Issues

open closed Total
Assigned issues 35 830 865
Reported issues 61 496 557

Projects

Project Roles Registered on
Suricata Developer, OISF Team 12/05/2018
Suricata-Update Developer, OISF Team 12/05/2018

Activity

Today

PA 12:17 PM Suricata Bug #8577 (New): dcerpc: bind PDUs with 0 pfc_flags don't match without any_frag
> Based on Philippe's suggestion, I am rejecting this ticket
That is not what I meant
I meant the code change is less than one line, but the doc change should be much bigger...
Philippe Antoine

05/19/2026

PA 07:52 PM Suricata Bug #8577: dcerpc: bind PDUs with 0 pfc_flags don't match without any_frag
If we agree this is the desired behavior, we need mostly to update the doc Philippe Antoine
PA 07:50 PM Suricata Bug #8577: dcerpc: bind PDUs with 0 pfc_flags don't match without any_frag
Pcap is already merged in SV with previous ticket Philippe Antoine

05/17/2026

PA 07:37 PM Suricata Bug #8543 (Closed): decode/tcp: avoid unaligned access in TCP option parsing
https://github.com/OISF/suricata/pull/15376 Philippe Antoine
PA 07:35 PM Suricata Documentation #8567 (Triaged): doc: improve manpage of suricatasc (8.0.x backport)
Philippe Antoine
PA 07:33 PM Suricata Task #8535 (Triaged): psl: crate should be updated on every release (8.0.x backport)
Philippe Antoine
PA 07:32 PM Suricata Task #8532 (Triaged): suricata-verify: ensure CI covers all tests
Philippe Antoine
PA 07:32 PM Suricata Documentation #8563 (In Review): doc: improve manpage of suricatasc
Philippe Antoine
PA 07:21 PM Suricata Support #8534: Lua detect rule: args["buffer"] is always empty in match() - buffer content inaccessible
In Suricata 8.0, (unlike to 7 and before) the init function should not ask for the buffer anymore, see https://docs.suricata.io/en/suricata-8.0.4/rules/lua-detection.html
You should get it directly from the http lib or so
cc @jish
Philippe Antoine

05/16/2026

PA 06:54 PM Suricata Task #6476 (In Progress): ftp: parity of logging and detection buffers
@python3 scripts/eve-parity.py unmapped-fields | grep ^ftp@ still shows unmapped fields.
Should you just update the json schema ?
Philippe Antoine

Also available in: Atom