General

Profile

Giuseppe Longo

Issues

Projects

Activity

03/22/2018

08:42 AM Suricata Feature #2277: netinfo: structured information about the network. Output hierarchical network tree in events
The only one we have seen so far is device42 that is not really common and has a JSON output. Their format has far mo...

03/13/2018

09:01 AM Suricata Feature #2277: netinfo: structured information about the network. Output hierarchical network tree in events
We would use both JSON and YAML formats. Do you agree with that?

02/26/2018

02:29 AM Suricata Feature #2277: netinfo: structured information about the network. Output hierarchical network tree in events
The configuration consists in setting a json file that contains the information:...

02/12/2018

02:14 AM Suricata Feature #2277: netinfo: structured information about the network. Output hierarchical network tree in events
...

01/25/2018

08:45 AM Suricata Feature #2426 (New): tls: extend logging
TLS logging can be extended with the following fields:
- Subject public key algorithm
- Certificate signature algor...

01/09/2018

05:10 AM Suricata Feature #2285: modify memcaps over unix socket
Merged: https://github.com/OISF/suricata/pull/3102

12/20/2017

10:45 AM Suricata Feature #2388: smtp: log md5 of attachments
I have a patch that simply compute the md5 of the files related to a smtp state.
10:30 AM Suricata Feature #2388 (New): smtp: log md5 of attachments
SMTP events can be extended adding
md5 of attachments, example below:...
10:27 AM Suricata Feature #2387: smtp: extend probing parser
Most of the servers answers via 220 message
when a client connects.
So it can be used to detect smtp protocol.
10:27 AM Suricata Feature #2387 (New): smtp: extend probing parser
Most of the servers answers via 220 message
when a client connects.
So it can be used to detect smtp protocol.

Also available in: Atom