mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00
![]() When a CREATE request contains the FILE_DELETE_ON_CLOSE option and the subsequent CREATE response indicates success, we now raise the smb2_file_delete event to log a delete action in smb_files.log and also give users a way to handle this scenario. The provided pcap was generated locally by recording a smbtorture run of the smb2.delete-on-close-perms test case. Placed the create_options into the CmdInfo record for potential exposure in smb_cmd.log (wasn't sure how that would look so left it for the future). Fixes #2276. |
||
---|---|---|
.. | ||
__load__.zeek | ||
const-dos-error.zeek | ||
const-nt-status.zeek | ||
consts.zeek | ||
dpd.sig | ||
files.zeek | ||
main.zeek | ||
README | ||
smb1-main.zeek | ||
smb2-main.zeek |
Support for SMB protocol analysis.