Skip to content

Commit

Permalink
Adds test for enip
Browse files Browse the repository at this point in the history
Ticket: #3886
  • Loading branch information
catenacyber authored and victorjulien committed Jul 6, 2023
1 parent 746b5c0 commit 0a8596b
Show file tree
Hide file tree
Showing 4 changed files with 21 additions and 0 deletions.
7 changes: 7 additions & 0 deletions tests/enip-alert/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Description

Test ENIP alerts numbers

# PCAP

The pcap comes from https://redmine.openinfosecfoundation.org/issues/3886
Binary file added tests/enip-alert/enip_test1.pcap
Binary file not shown.
1 change: 1 addition & 0 deletions tests/enip-alert/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
alert enip any any -> any any (msg:"SURICATA enip test ";enip_command:99 ;sid:6450008; rev:1;)
13 changes: 13 additions & 0 deletions tests/enip-alert/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
requires:
min-version: 7

# disables checksum verification
args:
- -k none --set stream.midstream=true --set app-layer.protocols.enip.enabled=yes

checks:
- filter:
count: 2
match:
event_type: alert
alert.signature_id: 6450008

0 comments on commit 0a8596b

Please sign in to comment.