Project

General

Profile

Actions

Feature #4282

open

Ensure that the flags used for the initial TCP packets are saved

Added by Jeff Weeks almost 4 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
-
Effort:
Difficulty:
Label:

Description

Suricata saves the TCP flags which it sees inside `struct TcpStream_::tcp_flags` but this contains a union of all flags seen.
It can be beneficial to know the flags used solely in the first packet seen (in each direction).

No data to display

Actions

Also available in: Atom PDF