SMB: Name Lookup
This protocol anomaly is the \pipe\lsarpc (Local Security Authority) named pipe transaction used to execute the LookupAccountName function. Programs such as user2sid and Hyena use this named pipe transaction to validate usernames on the target host. This type of traffic is common between domain controllers. This protocol anomaly should be used to inspect WAN traffic only.
References
URL: http://www.systemtools.com http://www.chem.msu.su/~rudnyi/NT/sid.txt
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3