Anyone has any idea if there is anyway for suricata to detect IMAP data? Does suricata support alert “imap” or is there a way for us to capture the imap related packets?

alert imap any any <> any any (content: “Begin compression”; nocase; sid: 1000001; rev: 1; msg: “Keyword compression found”:wink:

alert imap is supported