Project

General

Profile

Actions

Feature #2727

open
EL SB

dcerpc: UUID to service name mapping

Feature #2727: dcerpc: UUID to service name mapping

Added by Eric Leblond over 7 years ago. Updated 3 days ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
low
Difficulty:
low
Label:

Description

Microsoft is proposing a DCERPC UID to name mapping. It is used by Zeek to allow mapping of UID to human understandable names (see https://github.com/bro/bro/blob/master/scripts/base/protocols/dce-rpc/consts.bro).

We could integrate that into dcerpc output to get more user friendly events.


Related issues 1 (1 open0 closed)

Related to Suricata - Feature #8523: dcerpc: map opnum to the function namesIn ReviewShivani BhardwajActions

EL Updated by Eric Leblond over 7 years ago Actions #1

  • Assignee set to Eric Leblond

VJ Updated by Victor Julien over 7 years ago Actions #2

  • Status changed from New to Assigned
  • Target version set to 5.0beta1

VJ Updated by Victor Julien about 7 years ago Actions #3

  • Priority changed from Normal to Low

VJ Updated by Victor Julien about 7 years ago Actions #4

  • Target version changed from 5.0beta1 to 70

VJ Updated by Victor Julien over 6 years ago Actions #5

  • Target version changed from 70 to TBD

VJ Updated by Victor Julien about 6 years ago Actions #6

  • Assignee changed from Eric Leblond to OISF Dev

VJ Updated by Victor Julien 22 days ago Actions #7

  • Related to Feature #8523: dcerpc: map opnum to the function names added

SB Updated by Shivani Bhardwaj 5 days ago Actions #8

  • Status changed from Assigned to In Progress
  • Assignee changed from OISF Dev to Shivani Bhardwaj
  • Priority changed from Low to Normal
  • Target version changed from TBD to 9.0.0-beta1

SB Updated by Shivani Bhardwaj 5 days ago Actions #9

  • Subject changed from DCERPC UID to name mapping to dcerpc: UUID to service name mapping

SB Updated by Shivani Bhardwaj 5 days ago Actions #10

  • Difficulty changed from medium to low

SB Updated by Shivani Bhardwaj 3 days ago Actions #11

  • Status changed from In Progress to In Review
Actions

Also available in: PDF Atom