mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00
Add a signature for SMB
This commit is contained in:
parent
6e842cf4da
commit
c63ad1cdcf
2 changed files with 8 additions and 1 deletions
|
@ -5,4 +5,6 @@
|
|||
@load ./pipe
|
||||
@load ./smb1-main
|
||||
@load ./smb2-main
|
||||
@load ./files
|
||||
@load ./files
|
||||
|
||||
@load-sigs ./dpd.sig
|
||||
|
|
5
scripts/base/protocols/smb/dpd.sig
Normal file
5
scripts/base/protocols/smb/dpd.sig
Normal file
|
@ -0,0 +1,5 @@
|
|||
signature dpd_smb {
|
||||
ip-proto == tcp
|
||||
payload /^....[\xfe\xff]SMB/
|
||||
enable "smb"
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue