4.17. MSRPC network traffic

4.17.1. MSRPC network traffic analysis with Ethereal
4.17.2. MSRPC network traffic analysis in Network Intrusion Prevention Systems
4.17.3. MSRPC network traffic analysis in Firewalls

As explained in Section 4.3, “MSRPC transports”, MSRPC was designed to be transport-independant, which implies that the MSRPC network traffic will be observed over different network protocols (TCP, UDP, SMB, HTTP).

Being able to analyze MSRPC network traffic is important for several reasons: