Anyone has any idea if there is anyway for suricata to detect IMAP data? Does suricata support alert “imap” or is there a way for us to capture the imap related packets?
alert imap any any <> any any (content: “Begin compression”; nocase; sid: 1000001; rev: 1; msg: “Keyword compression found”
i saw some similar question posted via the following links but would like to check if there is any further updates on this?
Many thanks in advance