Help in Suricata rule bitmask syntax problem
I have written the following rule in my Suricata rules file:
alert tcp any any <> any any (flow:established; content:"|65|"; offset:0; depth:1; byte_test:1, =, 3, 2, bitmask 0x03; msg:"detected"; classtype:bad-unk… Continue reading Help in Suricata rule bitmask syntax problem