DHCPv6 stash some notes

This commit is contained in:
Arne Welzel 2025-05-26 10:02:39 +02:00
parent 67caf581da
commit d7899e9d09
3 changed files with 95 additions and 0 deletions

View file

@ -0,0 +1,29 @@
Support for Dynamic Host Configuration Protocol (DHCP) analysis.
Log structure:
DHCPv4 logs transactions
We could also go [txid, iaid] and produce a log for each entry, but that'd
be the correct thing to do!
Probably overthinking if there's only ever a single IAID per transaction,
but in theory this is possible.
# What if there's no IAID? That's okay, too.
So... pivot on IAID?
State:
transaction_id: count
ianas: vector of IA_NA
# Common stuff
# Log entry
txid, ia_na.aid, iaaddr

View file

@ -0,0 +1,5 @@
# signature dhcpv6_todo {
# ip-proto == udp
# payload /^.{236}\x63\x82\x53\x63/
# enable "dhcpv6"
#}