Hello,
Guess having a brain short circuit moment, but I had the idea suricata also detects ntlm version as a seperate protocol like tls, smb ?
Cheers
Proud suricata beta 8 user
Hello,
Guess having a brain short circuit moment, but I had the idea suricata also detects ntlm version as a seperate protocol like tls, smb ?
Cheers
Proud suricata beta 8 user
Currently not, there is no dedicated NTLM parser but NTLM related parts in smb.