dcerpc dce_iface just match a packet (5.0.x backport)
The dce_iface dcerpc keyword just match the packet following the bind.
alert dcerpc any any -> any any (\ msg: "DCE Netlogon";\ flow: to_server;\ dce_iface: 12345678-1234-abcd-ef00-01234567cffb;\ sid: 1;\ )
Updated by Victor Julien 6 months ago
- Subject changed from dcerpc dce_iface just match a packet to dcerpc dce_iface just match a packet (5.0.x backport)
- Status changed from Assigned to Rejected
- Assignee deleted (
- Priority changed from High to Normal
- Target version deleted (
Closing as this is too intrusive for 5.0.x which is EOL soon.