mirror of
https://github.com/zeek/zeek.git
synced 2025-10-04 07:38:19 +00:00
add smb1_transaction2_secondary_request event
parse and expose SMB_COM_TRANSACTION2_SECONDARY (0x33) message to script level. See MS-CIFS section 2.2.4.47.1.
This commit is contained in:
parent
046c7bc481
commit
bbe89a79a4
6 changed files with 107 additions and 1 deletions
|
@ -2880,6 +2880,27 @@ export {
|
|||
data_displacement: count;
|
||||
};
|
||||
|
||||
type SMB1::Trans2_Sec_Args: record {
|
||||
## Total parameter count
|
||||
total_param_count: count;
|
||||
## Total data count
|
||||
total_data_count: count;
|
||||
## Parameter count
|
||||
param_count: count;
|
||||
## Parameter offset
|
||||
param_offset: count;
|
||||
## Parameter displacement
|
||||
param_displacement: count;
|
||||
## Data count
|
||||
data_count: count;
|
||||
## Data offset
|
||||
data_offset: count;
|
||||
## Data displacement
|
||||
data_displacement: count;
|
||||
## File ID
|
||||
FID: count;
|
||||
};
|
||||
|
||||
type SMB1::Find_First2_Request_Args: record {
|
||||
## File attributes to apply as a constraint to the search
|
||||
search_attrs : count;
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue