Project

General

Profile

Actions

Feature #8403

open
JF

smb: add samr_UserInfo details to EVE logs

Feature #8403: smb: add samr_UserInfo details to EVE logs

Added by Juliana Fajardini Reichow 29 days ago. Updated 28 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Target version:
Effort:
Difficulty:
Label:

Description

samr_UserInfo such as Account Name and Full Name is available in the SMB payload, and we can potentially
detect credential theft with them, but they're not exposed as JSON fields in our logs.

These are good candidates to be logged.

I've added a pcap to #5685 that has these fields as example on packet 339.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #5685: tracking: active directory protocols supportAssignedVictor JulienActions

VJ Updated by Victor Julien 28 days ago Actions #1

  • Description updated (diff)

VJ Updated by Victor Julien 28 days ago Actions #2

  • Related to Task #5685: tracking: active directory protocols support added
Actions

Also available in: PDF Atom