cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
728
Views
0
Helpful
2
Replies

RPC WinNuke

mlowery
Level 1
Level 1

All of a sudden, I've started getting alerts on RPC WinNuke Sig#:3345 from a domain controller to workstations on the internal network.

I am unable to find anything that has changed, nor can I find anything that would cause this event to be triggered.

Can anyone tell me if this is a known false-positive, or do I need to keep digging?

Thank you,

Michael

2 Replies 2

owillins
Level 6
Level 6

If possible could you please test this set up on a different sensor and check the results.

I have tried on two other sensors now, and it seems that this signature fires when traffic is sent to Windows 2000/2003 domain controllers.

Review Cisco Networking for a $25 gift card