Project

General

Profile

Actions

Feature #4175

open

dcerpc: higher level logging

Added by Victor Julien 10 months ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

At the 2020 brainstorm it was suggested that the DCERPC logging would support a higher level logging, as both dcerpc and smb can be very verbose. Zeek was mentioned as an example to look at. Concern was that it might hide evasion attempts.

A good start would be to get some examples.


Related issues

Related to Task #4097: Suricon 2020 brainstormNewVictor JulienActions
Actions #1

Updated by Victor Julien 10 months ago

  • Related to Task #4097: Suricon 2020 brainstorm added
Actions

Also available in: Atom PDF