All:
What the latest status on DECRPC inspection of MS Windows RPC DCOM on ASA platform?
There is discussion as far back as 2010/2011 (12 years ago) that the functionality was entirely broken with the latest versions of the protocol library from Microsoft.
Looking for an official statement/position from Cisco.
1) Is it re-written/repaired working in the Firepower product line?
2) Are most people configuring hosts to use explicit DCOM / RPC TCP port ranges, and then authorizing large ranges of ports in ACLs?