DCE_RPC
¶Namespace: | DCE_RPC |
---|---|
Imports: | base/frameworks/dpd, base/protocols/dce-rpc/consts.bro |
Source File: | /scripts/base/protocols/dce-rpc/main.bro |
DCE_RPC::ignored_operations : table &redef |
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks. |
DPD::ignore_violations : set &redef |
|
Log::ID : enum |
|
connection : record |
|
likely_server_ports : set &redef |
DCE_RPC::ignored_operations
¶Type: | table [string ] of set [string ] |
---|---|
Attributes: | &redef |
Default: |
{
["wkssvc"] = {
"NetrWkstaGetInfo"
},
["winreg"] = {
"BaseRegCloseKey",
"BaseRegOpenKey",
"OpenClassesRoot",
"BaseRegEnumKey",
"OpenLocalMachine",
"BaseRegQueryValue",
"BaseRegDeleteKeyEx",
"BaseRegGetVersion"
},
["spoolss"] = {
"RpcSplOpenPrinter",
"RpcClosePrinter"
}
}
These are DCE-RPC operations that are ignored, typically due to the operations being noisy and low value on most networks.
DCE_RPC::BackingState
¶Type: |
info: state: |
---|
DCE_RPC::Info
¶Type: |
|
---|