Project

General

Profile

Actions

Task #7452

open

ldap: add keywords to match output

Added by Philippe Antoine 2 months ago. Updated 9 days ago.

Status:
New
Priority:
High
Target version:
Effort:
Difficulty:
Label:

Subtasks 4 (3 open1 closed)

Feature #7453: ldap: add ldap.request.operation and ldap.response.operation keywordsClosedAlice da Silva AkakiActions
Feature #7470: detect: add ldap.bind.version keywordNewAlice da Silva AkakiActions
Feature #7471: detect/ldap: add ldap.distinguished_name keywords for request and responseIn ReviewAlice da Silva AkakiActions
Feature #7550: detect: add keywords for ExtendedResponseNewAlice da Silva AkakiActions

Related issues 11 (9 open2 closed)

Related to Suricata - Feature #1199: protocol: LDAP supportClosedGiuseppe LongoActions
Related to Suricata - Feature #7477: ldap: add support for AbandonRequestClosedAlice da Silva AkakiActions
Related to Suricata - Feature #7535: detect: add ldap.search_request.filter and also log the filterNewAlice da Silva AkakiActions
Related to Suricata - Feature #7539: detect: add keyword ldap.mod_dn_request.new_rdnNewAlice da Silva AkakiActions
Blocks Suricata - Story #6597: rules: improve rules keyword/output parityNewVictor JulienActions
Blocked by Suricata - Feature #7532: detect: add keywords for LDAPResultIn ReviewAlice da Silva AkakiActions
Blocked by Suricata - Feature #7533: detect: add ldap.request.attribute_type and ldap.request.attribute keywords, and same for responsesNewAlice da Silva AkakiActions
Blocked by Suricata - Feature #7534: detect: add ldap.request.message_id and ldap.responses.message_idNewAlice da Silva AkakiActions
Blocked by Suricata - Feature #7536: detect: add keywords for BindRequestNewAlice da Silva AkakiActions
Blocked by Suricata - Feature #7537: detect: add keywords for SearchRequestNewAlice da Silva AkakiActions
Blocked by Suricata - Feature #7538: detect: keyword ldap.modify_request.operationNewAlice da Silva AkakiActions
Actions #1

Updated by Philippe Antoine 2 months ago

  • Blocks Story #6597: rules: improve rules keyword/output parity added
Actions #2

Updated by Philippe Antoine 2 months ago

  • Tracker changed from Feature to Task
Actions #3

Updated by Juliana Fajardini Reichow 2 months ago

Actions #4

Updated by Philippe Antoine 2 months ago

  • Subtask #7453 added
Actions #5

Updated by Philippe Antoine 2 months ago

  • Subtask #7470 added
Actions #6

Updated by Philippe Antoine 2 months ago

  • Subtask #7471 added
Actions #7

Updated by Alice da Silva Akaki about 2 months ago

  • Related to Feature #7477: ldap: add support for AbandonRequest added
Actions #8

Updated by Philippe Antoine 29 days ago

List of keywords to add :
- ldap.dn : buffer , maps to bind_request.name, search_request.base_object, etc... # comment if there is something to say
- ldap.result.code : integer

First, the generic keywords that work for multiple operations, based on the LDAP ASN1 definition

And then the remaining fields in json schema like bind_request.version, ordered by priority

Actions #9

Updated by Philippe Antoine 19 days ago

  • Blocked by Feature #7532: detect: add keywords for LDAPResult added
Actions #10

Updated by Philippe Antoine 19 days ago

  • Blocked by Feature #7533: detect: add ldap.request.attribute_type and ldap.request.attribute keywords, and same for responses added
Actions #11

Updated by Philippe Antoine 19 days ago

  • Blocked by Feature #7534: detect: add ldap.request.message_id and ldap.responses.message_id added
Actions #12

Updated by Philippe Antoine 19 days ago

  • Related to Feature #7535: detect: add ldap.search_request.filter and also log the filter added
Actions #13

Updated by Philippe Antoine 19 days ago

  • Blocked by Feature #7536: detect: add keywords for BindRequest added
Actions #14

Updated by Philippe Antoine 19 days ago

  • Blocked by Feature #7537: detect: add keywords for SearchRequest added
Actions #15

Updated by Philippe Antoine 19 days ago

  • Blocked by Feature #7538: detect: keyword ldap.modify_request.operation added
Actions #16

Updated by Philippe Antoine 19 days ago

  • Related to Feature #7539: detect: add keyword ldap.mod_dn_request.new_rdn added
Actions #17

Updated by Philippe Antoine 15 days ago

  • Subtask #7550 added
Actions

Also available in: Atom PDF