DCE_RPC| Namespace: | DCE_RPC |
|---|---|
| Imports: | base/frameworks/dpd, base/protocols/dce-rpc/consts.bro |
| Source File: | /scripts/base/protocols/dce-rpc/main.bro |
DCE_RPC::ignored_operations: table &redef |
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks. |
DPD::ignore_violations: set &redef |
|
Log::ID: enum |
|
connection: record |
|
likely_server_ports: set &redef |
DCE_RPC::ignored_operations| Type: | table [string] of set [string] |
|---|---|
| Attributes: | &redef |
| Default: |
{
["wkssvc"] = {
"NetrWkstaGetInfo"
},
["winreg"] = {
"BaseRegCloseKey",
"BaseRegDeleteKeyEx",
"OpenLocalMachine",
"BaseRegEnumKey",
"BaseRegQueryValue",
"BaseRegGetVersion",
"BaseRegOpenKey",
"OpenClassesRoot"
},
["spoolss"] = {
"RpcClosePrinter",
"RpcSplOpenPrinter"
}
}
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks.
DCE_RPC::BackingState| Type: |
info: state: |
|---|
DCE_RPC::Info| Type: |
|
|---|