Actions
Feature #7095
openrdp: keywords additions
Description
While Suricata generates RDP protocol logs itself , it is often useful to have rdp keywords available so custom signatures can be developed.
Currently we have none.
- rdp client version
- rdp client name
- rdp client cookie
- rdp cleint build
- rdp client keyboard type
- rdp x509 serial
The screenshot attached are Kibana visualizations from the regular protocol log (event_type rdp) produced by Suricata
Files
Updated by Jason Ish 4 months ago
- Related to Story #6597: rules: improve rules keyword/output parity added
Updated by Philippe Antoine 4 months ago
- Related to Optimization #3304: generic way to register buffers for logging and detection added
Updated by Lukas Sismis 4 months ago
- Related to Feature #7100: smb: additional keywords added
Updated by Lukas Sismis 4 months ago
- Related to deleted (Feature #7100: smb: additional keywords)
Updated by Victor Julien 4 months ago
- Subject changed from rdp keywords additions to rdp: keywords additions
Actions