Namespace: | DCE_RPC |
---|---|
Imports: | base/frameworks/dpd, base/protocols/dce-rpc/consts.bro |
Source File: | /scripts/base/protocols/dce-rpc/main.bro |
DCE_RPC::ignored_operations: table &redef | These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks. |
DPD::ignore_violations: set &redef | |
Log::ID: enum | |
connection: record | |
likely_server_ports: set &redef |
Type : | table [string] of set [string] |
---|---|
Attributes : | &redef |
Default : |
{
["wkssvc"] = {
"NetrWkstaGetInfo"
},
["spoolss"] = {
"RpcSplOpenPrinter",
"RpcClosePrinter"
},
["winreg"] = {
"OpenClassesRoot",
"BaseRegGetVersion",
"BaseRegEnumKey",
"BaseRegQueryValue",
"OpenLocalMachine",
"BaseRegDeleteKeyEx",
"BaseRegCloseKey",
"BaseRegOpenKey"
}
}
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks.
Type : |
info: DCE_RPC::Info state: DCE_RPC::State |
---|
Type : |
|
---|