Actions
Bug #4928
closeddcerpc dce_iface just match a packet (5.0.x backport)
Status:
Rejected
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:
Description
The dce_iface dcerpc keyword just match the packet following the bind.
alert dcerpc any any -> any any (\
msg: "DCE Netlogon";\
flow: to_server;\
dce_iface: 12345678-1234-abcd-ef00-01234567cffb;\
sid: 1;\
)
Files
Actions