Skip to content

Commit

Permalink
WIP pkt:flow_start hook test
Browse files Browse the repository at this point in the history
  • Loading branch information
victorjulien committed Feb 26, 2025
1 parent 15de63c commit 1e1194c
Show file tree
Hide file tree
Showing 2 changed files with 38 additions and 0 deletions.
5 changes: 5 additions & 0 deletions tests/rule-hooks/pkt-hook-flow-start-01/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
alert tcp:flow_start any any -> any any (seq:123; sid:1;)
alert tcp:flow_start any any -> any any (dsize:0; sid:2;)
alert tcp:flow_start any any -> any any (sid:3;)
alert ip:flow_start any any -> any any (sid:4;)
alert ip:flow_start any any -> any any (flow:to_server; sid:5;)
33 changes: 33 additions & 0 deletions tests/rule-hooks/pkt-hook-flow-start-01/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
pcap: ../http-body-hook-01/input.pcap

checks:
- filter:
count: 1
match:
event_type: http
http.url: "/~regit/ids-suricata-esiea.pdf"
- filter:
count: 0
match:
event_type: alert
alert.signature_id: 1
- filter:
count: 2
match:
event_type: alert
alert.signature_id: 2
- filter:
count: 2
match:
event_type: alert
alert.signature_id: 3
- filter:
count: 2
match:
event_type: alert
alert.signature_id: 4
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 5

0 comments on commit 1e1194c

Please sign in to comment.