diff --git a/scripts/base/protocols/smb/__load__.bro b/scripts/base/protocols/smb/__load__.bro index bfaf121fe1..0d9de8c984 100644 --- a/scripts/base/protocols/smb/__load__.bro +++ b/scripts/base/protocols/smb/__load__.bro @@ -5,4 +5,6 @@ @load ./pipe @load ./smb1-main @load ./smb2-main -@load ./files \ No newline at end of file +@load ./files + +@load-sigs ./dpd.sig diff --git a/scripts/base/protocols/smb/dpd.sig b/scripts/base/protocols/smb/dpd.sig new file mode 100644 index 0000000000..c7bd691cb5 --- /dev/null +++ b/scripts/base/protocols/smb/dpd.sig @@ -0,0 +1,5 @@ +signature dpd_smb { + ip-proto == tcp + payload /^....[\xfe\xff]SMB/ + enable "smb" +} \ No newline at end of file