RPC or Not, Here We Log: Preventing Exploitation and Abuse with RPC Firewall
ID: f26cc20f-0f9a-56b9-a334-b5b1f0752c94
STIX ID: report--f26cc20f-0f9a-56b9-a334-b5b1f0752c94
Feed Name: NVISO Labs
This post introduces the Zero Networks RPC Firewall and demonstrates how to create and deploy rules to audit or block Windows RPC calls, with a practical focus on preventing DCSync by controlling DRSUAPI DRSGetNCChanges traffic (UUID e3514235-4b06-11d1-ab04-00c04fc2dcd2, opnum 3). It explains identifying RPC UUIDs and operation numbers, defining allowed endpoints, selecting actions and auditing, and handling differences between RPC filters when LSA Protection is enabled versus full firewall rules when it is disabled, while also highlighting relevant event logs and providing example configurations and deployment guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
