Project

General

Profile

Actions

Feature #7565

closed

dcerpc: rpc interfaces info in request event

Added by Shivani Bhardwaj about 1 month ago. Updated about 1 month ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
low
Difficulty:
Label:

Description

RPC interface information comes with a BIND request for DCERPC which Suricata did log. However, the feedback from community was that the REQUEST type request should also carry this information for an easy correlation. Otherwise, one has to find the BIND request event for the same flow_id as a REQUEST request and find this information.

Actions #1

Updated by Shivani Bhardwaj about 1 month ago

  • Status changed from Assigned to In Review
Actions #2

Updated by Shivani Bhardwaj about 1 month ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF