DCE_RPC¶| Namespace: | DCE_RPC | 
|---|---|
| Imports: | base/frameworks/dpd, base/protocols/dce-rpc/consts.bro | 
| Source File: | /scripts/base/protocols/dce-rpc/main.bro | 
| DCE_RPC::ignored_operations:table&redef | These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks. | 
| DPD::ignore_violations:set&redef | |
| Log::ID:enum | |
| connection:record | |
| likely_server_ports:set&redef | 
DCE_RPC::ignored_operations¶| Type: | table[string] ofset[string] | 
|---|---|
| Attributes: | &redef | 
| Default: | 
{
   ["wkssvc"] = {
      "NetrWkstaGetInfo"
   },
   ["spoolss"] = {
      "RpcSplOpenPrinter",
      "RpcClosePrinter"
   },
   ["winreg"] = {
      "BaseRegCloseKey",
      "OpenLocalMachine",
      "BaseRegQueryValue",
      "BaseRegDeleteKeyEx",
      "OpenClassesRoot",
      "BaseRegGetVersion",
      "BaseRegOpenKey",
      "BaseRegEnumKey"
   }
}
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks.
DCE_RPC::BackingState¶| Type: | info:  state:  | 
|---|
DCE_RPC::Info¶| Type: | 
 | 
|---|
