Project

General

Profile

Actions

Feature #5413

closed

DCERPC logging is not easy to use in analysis

Added by Eric Leblond almost 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

The dcerpc part of smb events have the dcerpc uudi in one event and the opnum in another event. This is not convenient as a full understanding of the dcerpc request needs to be build upon 2 events.


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #4175: dcerpc: higher level loggingNewCommunity TicketActions
Related to Suricata - Bug #5814: smb: duplicate interface fields loggedClosedJason IshActions
Actions

Also available in: Atom PDF