Actions
Bug #4927
closeddcerpc dce_iface just match a packet
Affected Versions:
Effort:
Difficulty:
Label:
Description
The dce_iface dcerpc keyword just match the packet following the bind.
alert dcerpc any any -> any any (\ msg: "DCE Netlogon";\ flow: to_server;\ dce_iface: 12345678-1234-abcd-ef00-01234567cffb;\ sid: 1;\ )
Files
Actions