mirror of
https://github.com/zeek/zeek.git
synced 2025-10-05 16:18:19 +00:00
Filter out another very common DCE/RPC operation.
This commit is contained in:
parent
bcdba4cc5d
commit
d35adca9c5
1 changed files with 1 additions and 1 deletions
|
@ -26,7 +26,7 @@ export {
|
|||
};
|
||||
|
||||
const ignored_operations: table[string] of set[string] = {
|
||||
["winreg"] = set("BaseRegCloseKey", "BaseRegGetVersion", "BaseRegOpenKey", "BaseRegQueryValue", "BaseRegDeleteKeyEx", "OpenLocalMachine", "BaseRegEnumKey"),
|
||||
["winreg"] = set("BaseRegCloseKey", "BaseRegGetVersion", "BaseRegOpenKey", "BaseRegQueryValue", "BaseRegDeleteKeyEx", "OpenLocalMachine", "BaseRegEnumKey", "OpenClassesRoot"),
|
||||
["spoolss"] = set("RpcSplOpenPrinter", "RpcClosePrinter"),
|
||||
["wkssvc"] = set("NetrWkstaGetInfo"),
|
||||
} &redef;
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue