DCE_RPC¶| Namespace: | DCE_RPC |
|---|---|
| Imports: | base/frameworks/dpd, base/protocols/dce-rpc/consts.bro |
| Source File: | /scripts/base/protocols/dce-rpc/main.bro |
DCE_RPC::ignored_operations: table &redef |
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks. |
DPD::ignore_violations: set &redef |
|
Log::ID: enum |
|
connection: record |
|
likely_server_ports: set &redef |
DCE_RPC::ignored_operations¶| Type: | table [string] of set [string] |
|---|---|
| Attributes: | &redef |
| Default: |
{
["wkssvc"] = {
"NetrWkstaGetInfo"
},
["spoolss"] = {
"RpcSplOpenPrinter",
"RpcClosePrinter"
},
["winreg"] = {
"BaseRegCloseKey",
"OpenLocalMachine",
"BaseRegQueryValue",
"BaseRegDeleteKeyEx",
"OpenClassesRoot",
"BaseRegGetVersion",
"BaseRegOpenKey",
"BaseRegEnumKey"
}
}
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks.
DCE_RPC::BackingState¶| Type: |
info: state: |
|---|
DCE_RPC::Info¶| Type: |
|
|---|