next up previous contents
Next: Changing content behavior Up: content Previous: Format   Contents

Examples

    alert tcp any any -> any 139 (content:"|5c 00|P|00|I|00|P|00|E|00 5c|";)

    alert tcp any any -> any 80 (content:!"GET";)

Note:  

A ! modifier negates the results of the entire content search, modifiers included. For example, if using content:!"A"; within:50; and there are only 5 bytes of payload and there is no "A" in those 5 bytes, the result will return a match. If there must be 50 bytes for a valid match, use isdataat as a pre-cursor to the content.



Eugene Misnik 2013-05-08