diff --git a/tests/sig-shadow.rules b/tests/sig-shadow.rules new file mode 100644 index 0000000..06aaee2 --- /dev/null +++ b/tests/sig-shadow.rules @@ -0,0 +1,2 @@ +alert http any any -> any any (msg:"test"; http.host; content:"romeo"; sid:1; rev:1;) +alert http any any -> any any (msg:"test"; http.host; content:"juliette"; sid:1; rev:2;)