From 6966e0d19b389f78c97f55ab3b2318a5cda41e08 Mon Sep 17 00:00:00 2001 From: Luca Deri Date: Wed, 11 Sep 2019 17:13:49 +0200 Subject: Added STUN check to avoid false positives Added fingerprint comments in SSH/TLS Added netflow test pcap --- tests/pcap/netflowv9.pcap | Bin 0 -> 14072 bytes tests/result/netflowv9.pcap.out | 3 +++ 2 files changed, 3 insertions(+) create mode 100644 tests/pcap/netflowv9.pcap create mode 100644 tests/result/netflowv9.pcap.out (limited to 'tests') diff --git a/tests/pcap/netflowv9.pcap b/tests/pcap/netflowv9.pcap new file mode 100644 index 000000000..e9f34db42 Binary files /dev/null and b/tests/pcap/netflowv9.pcap differ diff --git a/tests/result/netflowv9.pcap.out b/tests/result/netflowv9.pcap.out new file mode 100644 index 000000000..9f6f3080a --- /dev/null +++ b/tests/result/netflowv9.pcap.out @@ -0,0 +1,3 @@ +NetFlow 10 13888 1 + + 1 UDP 192.168.2.134:48629 -> 192.168.2.222:2057 [proto: 128/NetFlow][cat: Network/14][10 pkts/13888 bytes -> 0 pkts/0 bytes][bytes ratio: 1.000 (Upload)][IAT c2s/s2c min/avg/max/stddev: 0/0 0.0/0.0 0/0 0.0/0.0][Pkt Len c2s/s2c min/avg/max/stddev: 1362/0 1388.8/0.0 1418/0 23.1/0.0] -- cgit v1.2.3