jasonish/py-idstools

Feature request: xbits parsing support

Opened this issue · 0 comments

As now the rule parser can extract flowbits, which are also used to check for never-triggering rule (see https://github.com/jasonish/py-idstools/blob/master/idstools/scripts/rulecat.py#L563).

It would be nice if this kind of processing could also be done using xbits.