SMB: DCERPC Unexpected Response

This anomaly triggers when it detects packets containing known evasion techniques that affect the SMB, DCE, RPC, and MS RPC protocols. These packets are normally not seen in traffic and indicate attempts to evade network defense systems by sending invalid, out of order, or heavily fragmented communications. Use this signature only at WAN borders to reduce false positive possibilities.

Short Name
SMB:AUDIT:DCERPC-UNEXPECTED-RSP
Severity
Minor
Recommended
False
Recommended Action
None
Category
SMB
Release Date
08/09/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Occasionally

Found a potential security threat?