You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 80444e5
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/logging.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -96,7 +96,7 @@ Example shape:
96
96
|`opcua` (TCP) | Array of per-direction frames: `direction`, `command`, `path`, `message_type`, `service`, `endpoint_url`, `security_policy`, `application_uri`, `application_name`, `username`, `payload`|`command` is `service` (or `message_type` if empty). `path` copies `endpoint_url`. Username identity is recorded; password bytes are not copied into `decoded`. |
97
97
|`mongodb` (TCP) | Array of per-direction frames: `direction`, `header`, `opcode_str`, `command`, `status`, `payload`|`command` is the BSON command name. Writes set `status``ok`. |
98
98
|`mcp` (TCP) | Array of per-direction frames: `direction`, `command`, `path`, `status`, `session_id`, `payload`|`command` is the JSON-RPC method or HTTP verb. Writes set HTTP `status`. Shares the idle session table with HTTP. |
99
-
|`telnet` (TCP) | Array of per-direction frames: `direction`, `command`, `message`| Login reads set `command``username`/`password`; shell reads use the first token. IAC negotiation is a separate `read` frame with no command. |
99
+
|`telnet` (TCP) | Array of per-direction frames: `direction`, `command`, `path`, `message`, `payload_hash`| Login reads set `command``username`/`password`; shell reads use the first token. `wget`/`curl` lines set `path` to the http(s) URL and `payload_hash` when the sample fetch succeeds. IAC negotiation is a separate `read` frame with no command. Process log: Info `telnet login` with `src_ip`/`src_port`/`dest_port`/`username`/`password`; shell lines at Debug. |
100
100
|`smtp` (TCP) | Array of per-direction frames: `direction`, `command`, `status`, `payload`| Reads set `command` to the SMTP verb. Writes set `status` to the 3-digit reply code. |
101
101
|`ftp` (TCP) | Array of per-direction frames: `direction`, `command`, `path`, `status`, `payload`, `payload_hash`|`command` is the FTP verb. STOR/RETR set `path`. Writes set `status` to the numeric reply code. |
102
102
|`rfb` (TCP) | Array of per-direction frames: `direction`, `command`, `payload`|`command` is `ProtocolVersion`, `Security`, `ServerInit`, or `ClientInit`. |
0 commit comments