mirror of
https://github.com/zeek/zeek.git
synced 2025-10-12 19:48:20 +00:00
![]() This is similar to what the external corelight/zeek-smb-clear-state script does, but leverages the smb2_discarded_messages_state() event instead of regularly checking on the state of SMB connections. The pcap was created using the dperson/samba container image and mounting a share with Linux's CIFS filesystem, then copying the content of a directory with 100 files. The test uses a BPF filter to imitate mostly "half-duplex" traffic. |
||
---|---|---|
.. | ||
compression-cap.zeek | ||
disabled-dce-rpc.test | ||
raw-ntlm.test | ||
smb1-OSS-fuzz-54883.test | ||
smb1-transaction-dcerpc.test | ||
smb1-transaction-request.test | ||
smb1-transaction-response.test | ||
smb1-transaction-secondary-request.test | ||
smb1-transaction2-request.test | ||
smb1-transaction2-secondary-request.test | ||
smb1.test | ||
smb2-create-delete-on-close.zeek | ||
smb2-fscontrol.test | ||
smb2-max-pending-messages.test | ||
smb2-read-write.zeek | ||
smb2-write-response.test | ||
smb2.test | ||
smb3-multichannel.test | ||
smb3-negotiate-context.test | ||
smb3.test | ||
smb311.test |