<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>File-Extraction on Inliniac</title>
    <link>https://inliniac.net/blog/tag/file-extraction/</link>
    <description>Recent content in File-Extraction on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Tue, 11 Nov 2014 10:47:42 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/tag/file-extraction/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SMTP file extraction in Suricata</title>
      <link>https://inliniac.net/blog/2014/11/11/smtp-file-extraction-in-suricata/</link>
      <pubDate>Tue, 11 Nov 2014 10:47:42 +0000</pubDate>
      <guid>https://inliniac.net/blog/2014/11/11/smtp-file-extraction-in-suricata/</guid>
      <description>&lt;p&gt;In &lt;a href=&#34;http://suricata-ids.org/2014/11/06/suricata-2-1beta2-available/&#34;&gt;2.1beta2&lt;/a&gt; the long awaited SMTP file extraction support for Suricata finally appeared. It has been a long development cycle. Originally started by BAE Systems, it was picked up by Tom Decanio of FireEye Forensics Group (formerly nPulse Technologies) followed by a last round of changes from my side. But it&amp;rsquo;s here now.&lt;/p&gt;&#xA;&lt;p&gt;It contains:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;a MIME decoder&lt;/li&gt;&#xA;&lt;li&gt;updates to the SMTP parser to use the MIME decoder for extracting files&lt;/li&gt;&#xA;&lt;li&gt;SMTP JSON log, integrated with EVE&lt;/li&gt;&#xA;&lt;li&gt;SMTP message URL extraction and logging&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As it uses the Suricata file handling API, it shares almost everything with the existing file handling for HTTP. The rule keyword work and the various logs work automatically with SMTP as well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>File extraction in Suricata</title>
      <link>https://inliniac.net/blog/2011/11/29/file-extraction-in-suricata/</link>
      <pubDate>Tue, 29 Nov 2011 16:27:27 +0000</pubDate>
      <guid>https://inliniac.net/blog/2011/11/29/file-extraction-in-suricata/</guid>
      <description>&lt;p&gt;Today I pushed out a new feature in Suricata I&amp;rsquo;m very excited about. It has been long in the making and with over 6000 new lines of code it&amp;rsquo;s a significant effort. It&amp;rsquo;s available in the current git master. I&amp;rsquo;d consider it alpha quality, so handle with care.&lt;/p&gt;&#xA;&lt;p&gt;So what is this all about? Simply put, we can now extract files from HTTP streams in Suricata. Both uploads and downloads. Fully controlled by the rule language. But thats not all. I&amp;rsquo;ve added a touch of magic. By utilizing libmagic (this powers the &amp;ldquo;file&amp;rdquo; command), we know the file type of files as well. Lots of interesting stuff that can be done there.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
