diff --git a/tests/dns/dns-response/test.pcap b/tests/dns/dns-response/test.pcap new file mode 100644 index 000000000..13684c3cb Binary files /dev/null and b/tests/dns/dns-response/test.pcap differ diff --git a/tests/dns/dns-response/test.rules b/tests/dns/dns-response/test.rules new file mode 100644 index 000000000..ee1475687 --- /dev/null +++ b/tests/dns/dns-response/test.rules @@ -0,0 +1,4 @@ +alert dns any any -> any any (msg:"DNS TEST response answer name"; dns.response.answer.name; content:"suricata.io"; sid:1; rev:1;) + +alert dns any any -> any any (msg:"DNS TEST request query name"; dns.query; content:"suricata.io"; sid:99; rev:1;) + diff --git a/tests/dns/dns-response/test.yaml b/tests/dns/dns-response/test.yaml new file mode 100644 index 000000000..974325b9b --- /dev/null +++ b/tests/dns/dns-response/test.yaml @@ -0,0 +1,10 @@ +# requires: +# min-version: 7 + +checks: + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1 + dns.answer.rrname: "suricata.io"