General

Profile

HA Hadiqa Alamdar Bukhari

  • Login: hadiqaalamdar
  • Registered on: 10/02/2023
  • Last sign in: 12/12/2023

Issues

open closed Total
Assigned issues 0 6 6
Reported issues 0 1 1

Projects

Project Roles Registered on
Suricata Developer 10/03/2023
Suricata-Update Developer 10/03/2023

Activity

01/22/2024

HA 11:22 AM Suricata Feature #6666 (In Progress): dns: add keyword for dns rrtype: dns.rrtype
Hadiqa Alamdar Bukhari

01/09/2024

HA 11:28 AM Suricata Feature #6666 (Closed): dns: add keyword for dns rrtype: dns.rrtype
The rtype field is much like opcode or rcode. Hadiqa Alamdar Bukhari

01/04/2024

HA 06:48 PM Suricata Feature #5642: DNS: parity between log fields and detection
Jason Ish wrote in #note-8:
> Hadiqa Alamdar Bukhari wrote in #note-7:
> ...
Got it, thanks!
Hadiqa Alamdar Bukhari
HA 04:53 PM Suricata Feature #5642: DNS: parity between log fields and detection
The fields which have been implemented include:
- dns.query
- dns.opcode
- dns.rcode : in progress
- dns.answer.name
- dns.query.name
Awaiting further instructions on which fields to implement first.
Hadiqa Alamdar Bukhari
HA 04:46 PM Suricata Feature #5642: DNS: parity between log fields and detection
After comparing the dns fields in rust/src/dns/log.rs and schema.json files I've found the following fields to be missing in the schema.json file:
* aa boolean field is missing in the answer array. It is present in dns object properties...
Hadiqa Alamdar Bukhari

12/27/2023

HA 12:53 PM Suricata Story #6597 (In Progress): rules: improve rules keyword/output parity
Hadiqa Alamdar Bukhari
HA 12:07 PM Suricata Feature #6621 (In Progress): dns: add keyword for dns rcode: dns.rcode
Hadiqa Alamdar Bukhari

12/19/2023

HA 12:28 PM Suricata Feature #6621: dns: add keyword for dns rcode: dns.rcode
Can this keyword be negated? Hadiqa Alamdar Bukhari

12/12/2023

HA 09:38 AM Suricata Task #6356 (New): detect/analyzer: add more details for the tcp.hdr keyword
Hadiqa Alamdar Bukhari

10/26/2023

HA 10:15 PM Suricata Task #6356: detect/analyzer: add more details for the tcp.hdr keyword
https://docs.suricata.io/en/suricata-6.0.1/rules/http-keywords.html
https://docs.suricata.io/en/latest/rules/header-keywords.html#tcp-hdr
I've been looking into the code and documentation of the tcphdr keyword, and I had some questions...
Hadiqa Alamdar Bukhari

Also available in: Atom