Project

General

Profile

Actions

Feature #5413

closed

DCERPC logging is not easy to use in analysis

Added by Eric Leblond over 1 year ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

The dcerpc part of smb events have the dcerpc uudi in one event and the opnum in another event. This is not convenient as a full understanding of the dcerpc request needs to be build upon 2 events.


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #4175: dcerpc: higher level loggingNewCommunity TicketActions
Related to Suricata - Bug #5814: smb: duplicate interface fields loggedClosedJason IshActions
Actions #1

Updated by Victor Julien over 1 year ago

Actions #2

Updated by Victor Julien over 1 year ago

  • Status changed from In Progress to Closed
  • Target version changed from TBD to 7.0.0-beta1
Actions #3

Updated by Jason Ish about 1 year ago

  • Related to Bug #5814: smb: duplicate interface fields logged added
Actions

Also available in: Atom PDF