diff --git a/tests/dns/dns-dcerpc-reversed/input.pcap b/tests/dns/dns-dcerpc-reversed/input.pcap new file mode 100755 index 000000000..0a71017d3 Binary files /dev/null and b/tests/dns/dns-dcerpc-reversed/input.pcap differ diff --git a/tests/dns/dns-dcerpc-reversed/test.yaml b/tests/dns/dns-dcerpc-reversed/test.yaml new file mode 100644 index 000000000..a3bf03180 --- /dev/null +++ b/tests/dns/dns-dcerpc-reversed/test.yaml @@ -0,0 +1,39 @@ +requires: + min-version: 8.0.0 + +args: + - --set stream.midstream=true + +checks: + + - filter: + count: 1 + match: + event_type: dns + dns.type: request + src_ip: "172.28.255.122" + src_port: 54824 + dest_ip: "192.168.1.12" + dest_port: 53 + + - filter: + count: 1 + match: + event_type: dns + dns.type: response + dns.answers[0].rrtype: A + src_ip: "172.28.255.122" + src_port: 54824 + dest_ip: "192.168.1.12" + dest_port: 53 + + - filter: + count: 1 + match: + event_type: flow + app_proto: dns + src_ip: "172.28.255.122" + src_port: 54824 + dest_ip: "192.168.1.12" + dest_port: 53 +