DCE RPC (dcerpc)

Table 46. DCE RPC (dcerpc)

FieldField NameTypeDescription
dcerpc.array.actual_countActual CountUnsigned 32-bit integerActual Count: Actual number of elements in the array
dcerpc.array.max_countMax CountUnsigned 32-bit integerMaximum Count: Number of elements in the array
dcerpc.array.offsetOffsetUnsigned 32-bit integerOffset for first element in array
dcerpc.auth_ctx_idAuth Context IDUnsigned 32-bit integer 
dcerpc.auth_levelAuth levelUnsigned 8-bit integer 
dcerpc.auth_pad_lenAuth pad lenUnsigned 8-bit integer 
dcerpc.auth_rsrvdAuth RsrvdUnsigned 8-bit integer 
dcerpc.auth_typeAuth typeUnsigned 8-bit integer 
dcerpc.cn_ack_reasonAck reasonUnsigned 16-bit integer 
dcerpc.cn_ack_resultAck resultUnsigned 16-bit integer 
dcerpc.cn_ack_trans_idTransfer SyntaxString 
dcerpc.cn_ack_trans_verSyntax verUnsigned 32-bit integer 
dcerpc.cn_alloc_hintAlloc hintUnsigned 32-bit integer 
dcerpc.cn_assoc_groupAssoc GroupUnsigned 32-bit integer 
dcerpc.cn_auth_lenAuth LengthUnsigned 16-bit integer 
dcerpc.cn_bind_if_verInterface VerUnsigned 16-bit integer 
dcerpc.cn_bind_if_ver_minorInterface Ver MinorUnsigned 16-bit integer 
dcerpc.cn_bind_to_uuidInterface UUIDString 
dcerpc.cn_bind_trans_idTransfer SyntaxString 
dcerpc.cn_bind_trans_verSyntax verUnsigned 32-bit integer 
dcerpc.cn_call_idCall IDUnsigned 32-bit integer 
dcerpc.cn_cancel_countCancel countUnsigned 8-bit integer 
dcerpc.cn_ctx_idContext IDUnsigned 16-bit integer 
dcerpc.cn_flagsPacket FlagsUnsigned 8-bit integer 
dcerpc.cn_flags.cancel_pendingCancel PendingBoolean 
dcerpc.cn_flags.dneDid Not ExecuteBoolean 
dcerpc.cn_flags.first_fragFirst FragBoolean 
dcerpc.cn_flags.last_fragLast FragBoolean 
dcerpc.cn_flags.maybeMaybeBoolean 
dcerpc.cn_flags.mpxMultiplexBoolean 
dcerpc.cn_flags.objectObjectBoolean 
dcerpc.cn_flags.reservedReservedBoolean 
dcerpc.cn_frag_lenFrag LengthUnsigned 16-bit integer 
dcerpc.cn_max_recvMax Recv FragUnsigned 16-bit integer 
dcerpc.cn_max_xmitMax Xmit FragUnsigned 16-bit integer 
dcerpc.cn_num_ctx_itemsNum Ctx ItemsUnsigned 8-bit integer 
dcerpc.cn_num_protocolsNumber of protocolsUnsigned 8-bit integer 
dcerpc.cn_num_resultsNum resultsUnsigned 8-bit integer 
dcerpc.cn_num_trans_itemsNum Trans ItemsUnsigned 16-bit integer 
dcerpc.cn_protocol_ver_majorProtocol major versionUnsigned 8-bit integer 
dcerpc.cn_protocol_ver_minorProtocol minor versionUnsigned 8-bit integer 
dcerpc.cn_reject_reasonReject reasonUnsigned 16-bit integer 
dcerpc.cn_sec_addrScndry AddrString 
dcerpc.cn_sec_addr_lenScndry Addr lenUnsigned 16-bit integer 
dcerpc.cn_statusStatusUnsigned 32-bit integer 
dcerpc.dg_act_idActivitiyString 
dcerpc.dg_ahintActivity HintUnsigned 16-bit integer 
dcerpc.dg_auth_protoAuth protoUnsigned 8-bit integer 
dcerpc.dg_cancel_idCancel IDUnsigned 32-bit integer 
dcerpc.dg_cancel_versCancel VersionUnsigned 32-bit integer 
dcerpc.dg_flags1Flags1Unsigned 8-bit integer 
dcerpc.dg_flags1_broadcastBroadcastBoolean 
dcerpc.dg_flags1_fragFragmentBoolean 
dcerpc.dg_flags1_idempotentIdempotentBoolean 
dcerpc.dg_flags1_last_fragLast FragmentBoolean 
dcerpc.dg_flags1_maybeMaybeBoolean 
dcerpc.dg_flags1_nofackNo FackBoolean 
dcerpc.dg_flags1_rsrvd_01ReservedBoolean 
dcerpc.dg_flags1_rsrvd_80ReservedBoolean 
dcerpc.dg_flags2Flags2Unsigned 8-bit integer 
dcerpc.dg_flags2_cancel_pendingCancel PendingBoolean 
dcerpc.dg_flags2_rsrvd_01ReservedBoolean 
dcerpc.dg_flags2_rsrvd_04ReservedBoolean 
dcerpc.dg_flags2_rsrvd_08ReservedBoolean 
dcerpc.dg_flags2_rsrvd_10ReservedBoolean 
dcerpc.dg_flags2_rsrvd_20ReservedBoolean 
dcerpc.dg_flags2_rsrvd_40ReservedBoolean 
dcerpc.dg_flags2_rsrvd_80ReservedBoolean 
dcerpc.dg_frag_lenFragment lenUnsigned 16-bit integer 
dcerpc.dg_frag_numFragment numUnsigned 16-bit integer 
dcerpc.dg_if_idInterfaceString 
dcerpc.dg_if_verInterface VerUnsigned 32-bit integer 
dcerpc.dg_ihintInterface HintUnsigned 16-bit integer 
dcerpc.dg_seqnumSequence numUnsigned 32-bit integer 
dcerpc.dg_serial_hiSerial HighUnsigned 8-bit integer 
dcerpc.dg_serial_loSerial LowUnsigned 8-bit integer 
dcerpc.dg_server_bootServer boot timeUnsigned 32-bit integer 
dcerpc.dg_statusStatusUnsigned 32-bit integer 
dcerpc.drepData RepresentationByte array 
dcerpc.drep.byteorderByte orderUnsigned 8-bit integer 
dcerpc.drep.characterCharacterUnsigned 8-bit integer 
dcerpc.drep.fpFloating-pointUnsigned 8-bit integer 
dcerpc.fack_max_frag_sizeMax Frag SizeUnsigned 32-bit integer 
dcerpc.fack_max_tsduMax TSDUUnsigned 32-bit integer 
dcerpc.fack_selackSelective ACKUnsigned 32-bit integer 
dcerpc.fack_selack_lenSelective ACK LenUnsigned 16-bit integer 
dcerpc.fack_serial_numSerial NumUnsigned 16-bit integer 
dcerpc.fack_versFACK VersionUnsigned 8-bit integer 
dcerpc.fack_window sizeWindow SizeUnsigned 16-bit integer 
dcerpc.fragmentDCE/RPC FragmentNo valueDCE/RPC Fragment
dcerpc.fragment.errorDefragmentation errorNo valueDefragmentation error due to illegal fragments
dcerpc.fragment.multipletailsMultiple tail fragments foundBooleanSeveral tails were found when defragmenting the packet
dcerpc.fragment.overlapFragment overlapBooleanFragment overlaps with other fragments
dcerpc.fragment.overlap.conflictConflicting data in fragment overlapBooleanOverlapping fragments contained conflicting data
dcerpc.fragment.toolongfragmentFragment too longBooleanFragment contained data past end of packet
dcerpc.fragmentsDCE/RPC FragmentsNo valueDCE/RPC Fragments
dcerpc.krb5_av.auth_verifierAuthentication VerifierByte array 
dcerpc.krb5_av.key_vers_numKey Version NumberUnsigned 8-bit integer 
dcerpc.krb5_av.prot_levelProtection LevelUnsigned 8-bit integer 
dcerpc.obj_idObjectString 
dcerpc.opOperationUnsigned 16-bit integer 
dcerpc.opnumOpnumUnsigned 16-bit integer 
dcerpc.pkt_typePacket typeUnsigned 8-bit integer 
dcerpc.referent_idReferent IDUnsigned 32-bit integerReferent ID for this NDR encoded pointer
dcerpc.request_inRequest inUnsigned 32-bit integerThis packet is a response to the packet in this frame
dcerpc.response_inResponse inUnsigned 32-bit integerThe response to this packet is in this packet
dcerpc.server_accepting_cancelsServer accepting cancelsBoolean 
dcerpc.verVersionUnsigned 8-bit integer 
dcerpc.ver_minorVersion (minor)Unsigned 8-bit integer