Project

General

Profile

Actions

Feature #4175

open

dcerpc: higher level logging

Added by Victor Julien almost 2 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

At the 2020 brainstorm it was suggested that the DCERPC logging would support a higher level logging, as both dcerpc and smb can be very verbose. Zeek was mentioned as an example to look at. Concern was that it might hide evasion attempts.

A good start would be to get some examples.


Related issues 2 (2 open0 closed)

Related to Task #4097: Suricon 2020 brainstormAssignedVictor JulienActions
Related to Feature #5413: DCERPC logging is not easy to use in analysisIn ProgressEric LeblondActions
Actions

Also available in: Atom PDF