Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
39 commits
Select commit Hold shift + click to select a range
a3ab00e
detect/dataset: add match subdomain option
antoineaboufayssal Mar 20, 2026
b09b048
doc/userguide: add dataset match subdomain documentation
antoineaboufayssal Mar 20, 2026
4144d9c
rust: format snmp files
catenacyber Jun 7, 2026
e390755
rust: check llmnr format
catenacyber Jun 7, 2026
955827b
util/path: handle missing d_type definitions on Solaris
l1gi Jun 2, 2026
cf65f76
build/solaris: use __sun and Solaris byteorder helpers
l1gi Jun 2, 2026
823322c
util/time: avoid tm_gmtoff on Solaris
l1gi Jun 2, 2026
1faa292
util/syslog: guard LOG_FTP for Solaris
l1gi Jun 2, 2026
f34acfd
util/cpu: enable SPARC misalignment emulation at startup
l1gi Jun 2, 2026
2ce2ebc
suricata: guard RLIMIT_NPROC usage
l1gi Jun 2, 2026
21d35f6
decoder/sctp: extend decoder
glongo Mar 6, 2026
bbd0ecb
detect/sctp: add sctp.hdr sticky buffer
glongo Mar 24, 2026
88f17d7
detect/sctp: add sctp.chunk_type keyword
glongo Mar 24, 2026
855f49b
detect/sctp: add sctp.chunk_cnt keyword
glongo Mar 24, 2026
2116c3c
detect/sctp: add sctp.vtag keyword
glongo Mar 24, 2026
ede1bce
output/json: add sctp metadata to alerts
glongo Mar 24, 2026
1413b08
decode/sctp: set p->payload to data chunk
glongo Mar 24, 2026
dc44447
detect/sctp: add sctp.chunk_data sticky buffer
glongo Mar 26, 2026
d892eb8
doc/sctp: add sctp keywords
glongo Mar 26, 2026
6150d61
github-actions: bump github/codeql-action from 4.36.1 to 4.36.2
dependabot[bot] Jun 9, 2026
39688a6
github-actions: bump codecov/codecov-action from 6.0.1 to 7.0.0
dependabot[bot] Jun 9, 2026
b2cd08b
util/log-redis: guard SCCalloc result for redis stream format
Jun 4, 2026
21bcbe1
detect/alert: guard SCStrdup result before use
Jun 4, 2026
01f64ea
detect/flowbits: check SCRealloc result before overwriting pointer
Jun 4, 2026
04a1de1
detect/reference: guard SCStrdup calls in DetectReferenceParse
Jun 4, 2026
2c16fb7
util/mpm-hs: fix null check parentheses; simplify SCHSConfigInit
Jun 4, 2026
7124fde
tests/fuzz: guard SCCalloc result in fuzz_decodebase64
Jun 4, 2026
344e89e
qa/cocci: fix broken regex alternation in malloc-error-check
Jun 9, 2026
3828de2
decode: propagate PacketAlertCreate failure instead of crashing
Jun 4, 2026
4d4c622
detect/parse: assert HashListTableLookup results in duplicate sig check
Jun 9, 2026
1715157
detect: guard rate filter callback registration, return bool on failure
Jun 9, 2026
3b5bdc4
examples: check rate filter callback registration result
Jun 9, 2026
0345b91
rust: exclude DETECT_BYTEMATH_ENDIAN_DEFAULT from bindings
inashivb Jun 10, 2026
3b9dc5a
output-json: avoid freeing caller-owned JSON builder
urvalkheni Jun 10, 2026
d64954a
detect: don't register unrelated inspect engines
victorjulien Jun 9, 2026
569d27e
detect: propagate inspect engine setup failures
victorjulien Jun 10, 2026
2a2cb40
detect: misc debug log additions
victorjulien Jun 10, 2026
b02fa53
detect: add helper for getting hook name
victorjulien Jun 10, 2026
d154484
detect/firewall: support hook LTE mode for built-in hooks
victorjulien Jun 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions .github/workflows/builds.yml
Original file line number Diff line number Diff line change
Expand Up @@ -918,7 +918,7 @@ jobs:
name: coverage-lcov-${{ github.job }}
path: coverage.lcov
- name: Upload coverage to Codecov
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f
with:
fail_ci_if_error: false
files: coverage.lcov
Expand Down Expand Up @@ -1631,7 +1631,7 @@ jobs:
name: coverage-lcov-${{ github.job }}
path: coverage.lcov
- name: Upload coverage to Codecov
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f
with:
fail_ci_if_error: false
files: coverage.lcov
Expand Down Expand Up @@ -1743,7 +1743,7 @@ jobs:
name: coverage-lcov-${{ github.job }}
path: coverage.lcov
- name: Upload coverage to Codecov
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f
with:
fail_ci_if_error: false
files: coverage.lcov
Expand Down Expand Up @@ -1894,7 +1894,7 @@ jobs:
name: coverage-lcov-${{ github.job }}
path: coverage.lcov
- name: Upload coverage to Codecov
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f
with:
fail_ci_if_error: false
files: coverage.lcov
Expand Down Expand Up @@ -2138,7 +2138,7 @@ jobs:
name: coverage-lcov-${{ github.job }}
path: coverage.lcov
- name: Upload coverage to Codecov
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f
with:
fail_ci_if_error: true
files: coverage.lcov
Expand Down Expand Up @@ -2356,7 +2356,7 @@ jobs:
name: coverage-lcov-${{ github.job }}
path: coverage.lcov
- name: Upload coverage to Codecov
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f
with:
fail_ci_if_error: false
files: coverage.lcov
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ jobs:

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v4.36.1
uses: github/codeql-action/init@v4.36.2
with:
languages: ${{ matrix.language }}
queries: security-extended
Expand All @@ -62,4 +62,4 @@ jobs:
./configure --enable-warnings --enable-unittests
make
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4.36.1
uses: github/codeql-action/analyze@v4.36.2
4 changes: 2 additions & 2 deletions .github/workflows/codeqlpy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ jobs:

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v4.36.1
uses: github/codeql-action/init@v4.36.2
with:
languages: ${{ matrix.language }}
queries: security-extended
Expand All @@ -64,4 +64,4 @@ jobs:
./configure --enable-warnings
make
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4.36.1
uses: github/codeql-action/analyze@v4.36.2
2 changes: 1 addition & 1 deletion .github/workflows/scorecards-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,6 @@ jobs:

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload SARIF results"
uses: github/codeql-action/upload-sarif@8ed7f7c384ef65d96d422e33fe592d3572522558 # v1
uses: github/codeql-action/upload-sarif@eda5730a8bfb740e03a28087a958444c646e5842 # v1
with:
sarif_file: results.sarif
32 changes: 29 additions & 3 deletions doc/userguide/rules/datasets.rst
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ Syntax::
dataset:<set|unset|isset|isnotset>,<name> \
[, type <string|md5|sha256|ipv4|ip>, save <file name>, load <file name>, state <file name>, memcap <size>, hashsize <size>
, format <csv|json|ndjson>, context_key <output_key>, value_key <json_key>, array_key <json_path>,
remove_key];
remove_key, match subdomain];

type <type>
the data type: string, md5, sha256, ipv4, ip
Expand Down Expand Up @@ -112,7 +112,11 @@ array_key <key>
remove_key
if set, the JSON object pointed by value key will be removed
from the alert event

match subdomain
if set to ``subdomain``, enables hierarchical domain matching.
On lookup, the dataset walks up the domain label hierarchy until
a match is found. Only valid with ``isset``/``isnotset`` commands
and ``type string``. Best used with the ``dotprefix`` transform.

.. note:: 'type' is mandatory and needs to be set.

Expand All @@ -137,6 +141,28 @@ on domain names to find TLDs in the dataset ``dns-tld-seen``:

.. image:: dataset-examples/detect-unique-tlds.png

3. Block domains and all their subdomains using a blocklist dataset:

.. container:: example-rule

reject dns any any -> any any (msg:"Blocked domain"; dns.query; dotprefix; dataset:isset,blocked-domains, type string, match subdomain, load blocked-domains.lst; sid:8000003; rev:1;)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is leading to a CI failure for Check rules doc: Error: detect-dataset: failed to set up dataset 'blocked-domains'. [DetectDatasetSetup:detect-dataset.c:640]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Commented on the PR as well...


The ``match subdomain`` option walks up the domain hierarchy on each
lookup. Combined with ``dotprefix``, a query for ``mail.evil.com``
becomes ``.mail.evil.com`` and is checked against the dataset as:
``.mail.evil.com``, ``.evil.com``, ``.com``. If ``.evil.com`` is in the
dataset, the rule matches.

The dataset file should contain entries with a leading dot::

LmV2aWwuY29tCg==

which is the base64 encoding of ``.evil.com``.

When using ``ndjson`` format, use the raw dotted value in the JSON::

{"domain": ".evil.com"}

Notice how it is not possible to do certain operations alone with datasets
(example 2 above), but, it is possible to use a combination of other rule
keywords. Keep in mind the cost of additional keywords though e.g. in the
Expand Down Expand Up @@ -184,7 +210,7 @@ Syntax::

dataset:<isset|isnotset>,<name> \
[, type <string|md5|sha256|ipv4|ip>, load <file name>, format <json|ndjson>, memcap <size>, hashsize <size>, context_key <json_key> \
, value_key <json_key>, array_key <json_path>];
, value_key <json_key>, array_key <json_path>, match subdomain];

Example rules could look like::

Expand Down
1 change: 1 addition & 0 deletions doc/userguide/rules/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ Suricata Rules
base64-keywords
sip-keywords
sdp-keywords
sctp-keywords
rfb-keywords
mqtt-keywords
ike-keywords
Expand Down
150 changes: 150 additions & 0 deletions doc/userguide/rules/sctp-keywords.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,150 @@
.. role:: example-rule-emphasis

SCTP Keywords
=============

Suricata supports sticky buffers and keywords for matching on SCTP
packet headers, chunks, and metadata.

Sticky buffers are expected to be followed by one or more
:doc:`payload-keywords`.

sctp.hdr
--------

Sticky buffer to match on the raw SCTP header and all chunks.

Example rule:

.. container:: example-rule

alert sctp any any -> any any (msg:"SCTP header match"; :example-rule-emphasis:`sctp.hdr; content:"|01|"; offset:8; depth:1;` sid:1; rev:1;)

``sctp.hdr`` is a 'sticky buffer'.

``sctp.hdr`` can be used as ``fast_pattern``.

sctp.chunk_data
---------------

Sticky buffer to match on any SCTP DATA chunk user payload.

When a packet contains DATA chunks, the packet payload (``p->payload``)
is set to the user data of the first DATA chunk. A bare ``content``
match (without a sticky buffer) therefore inspects the first DATA
chunk's payload. Use ``sctp.chunk_data`` to inspect all DATA chunks
independently.

Example rule:

.. container:: example-rule

alert sctp any any -> any any (msg:"SCTP DATA payload match"; :example-rule-emphasis:`sctp.chunk_data; content:"test";` sid:2; rev:1;)

``sctp.chunk_data`` is a 'sticky buffer'.

``sctp.chunk_data`` can be used as ``fast_pattern``.

sctp.vtag
---------

Match on the SCTP verification tag field in the common header.

sctp.vtag uses an :ref:`unsigned 32-bit integer <rules-integer-keywords>`.

Syntax::

sctp.vtag:[op]<number>

The verification tag can be matched exactly, or compared using the _op_ setting::

sctp.vtag:12345 # exactly 12345
sctp.vtag:>0 # greater than 0
sctp.vtag:100-200 # range 100 to 200

Example rule:

.. container:: example-rule

alert sctp any any -> any any (msg:"SCTP vtag match"; :example-rule-emphasis:`sctp.vtag:0;` sid:3; rev:1;)

sctp.chunk_type
---------------

Match on the type of any SCTP chunk in the packet.

sctp.chunk_type uses an :ref:`unsigned 8-bit integer <rules-integer-keywords>`.

Syntax::

sctp.chunk_type:[!]<value>
sctp.chunk_type:[op]<number>

Values can be specified by name or by numeric value. The following
named chunk types are supported:

================= =====
Name Value
================= =====
data 0
init 1
init_ack 2
sack 3
heartbeat 4
hb_ack 5
abort 6
shutdown 7
shutdown_ack 8
error 9
cookie_echo 10
cookie_ack 11
ecne 12
cwr 13
shutdown_complete 14
forward_tsn 192
================= =====

Named values are case-insensitive and can be negated with ``!``::

sctp.chunk_type:init # INIT chunk
sctp.chunk_type:init_ack # INIT ACK chunk
sctp.chunk_type:!data # any chunk that is not DATA

Numeric values support comparison operators and ranges::

sctp.chunk_type:1 # INIT chunk (type 1)
sctp.chunk_type:0-4 # range 0 to 4

Example rules:

.. container:: example-rule

alert sctp any any -> any any (msg:"SCTP INIT chunk detected"; :example-rule-emphasis:`sctp.chunk_type:init;` sid:4; rev:1;)

.. container:: example-rule

alert sctp any any -> any any (msg:"SCTP INIT chunk detected"; :example-rule-emphasis:`sctp.chunk_type:1;` sid:5; rev:1;)

sctp.chunk_cnt
--------------

Match on the number of SCTP chunks in the packet.

sctp.chunk_cnt uses an :ref:`unsigned 8-bit integer <rules-integer-keywords>`.

Syntax::

sctp.chunk_cnt:[op]<number>

The chunk count can be matched exactly, or compared using the _op_ setting::

sctp.chunk_cnt:1 # exactly 1 chunk
sctp.chunk_cnt:>3 # more than 3 chunks
sctp.chunk_cnt:2-5 # range 2 to 5

Example rule:

.. container:: example-rule

alert sctp any any -> any any (msg:"SCTP packet with multiple chunks"; :example-rule-emphasis:`sctp.chunk_cnt:>1;` sid:5; rev:1;)

Loading
Loading