Project

General

Profile

Actions

Feature #7566

open
SB SB

dcerpc: applayer events for anomalous parsing results

Feature #7566: dcerpc: applayer events for anomalous parsing results

Added by Shivani Bhardwaj about 1 year ago. Updated about 1 month ago.

Status:
Assigned
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

dcerpc lacks event handling which is important to convey what a possible issue could have led to an unexpected behavior.


Files

rough_potato_broken_2.pcap (143 KB) rough_potato_broken_2.pcap pcap with dcerpc Artem Kartunchikov, 04/02/2025 12:02 PM
stats.log (5.17 KB) stats.log Artem Kartunchikov, 04/02/2025 12:03 PM
packets_stats.log (10 KB) packets_stats.log Artem Kartunchikov, 04/02/2025 12:03 PM
locks_stats.log (1.52 KB) locks_stats.log Artem Kartunchikov, 04/02/2025 12:03 PM

Related issues 2 (1 open1 closed)

Related to Suricata - Bug #5133: dcerpc: logs not created after unhandled packet such as auth3ClosedPhilippe AntoineActions
Copied to Suricata - Feature #8426: rdp: applayer events for anomalous parsing resultsAssignedOISF DevActions
Actions

Also available in: PDF Atom