04-26-2005 08:37 AM - edited 03-10-2019 01:25 AM
All of a sudden, I've started getting alerts on RPC WinNuke Sig#:3345 from a domain controller to workstations on the internal network.
I am unable to find anything that has changed, nor can I find anything that would cause this event to be triggered.
Can anyone tell me if this is a known false-positive, or do I need to keep digging?
Thank you,
Michael
05-02-2005 06:28 AM
If possible could you please test this set up on a different sensor and check the results.
05-05-2005 04:47 AM
I have tried on two other sensors now, and it seems that this signature fires when traffic is sent to Windows 2000/2003 domain controllers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide