zeek/testing/btest/Baseline/scripts.base.protocols.dce-rpc.mapi/ntlm.log

11 lines
514 B
Text

#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path ntlm
#open 2018-08-16-22-12-09
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p username hostname domainname success status
#types time string addr port addr port string string string bool string
1056991898.902392 CwjjYJ2WqgTbAqiHl6 192.168.0.173 1068 192.168.0.2 4997 ALeonard ALEONARD-XP CNAMIS - -
1056991899.594334 C9mvWx3ezztgzcexV7 192.168.0.173 1073 192.168.0.2 1032 ALeonard ALEONARD-XP CNAMIS - -
#close 2018-08-16-22-12-09