Is MSRPC::DCOM:RemoteCreateInstance Request/Response decoder planned? And is this feature on demand?
asked 16 Jul '12, 05:24
As Wireshark is Open Source software primarily developed by people in their spare time, there isn't much of a plan.
Anyway, looking through Wireshark's source code I can see that packet-dcom-sysact.c appears to have some code that mentions RemoteCreateInstance so it would appear that Wireshark may already support this. I assume you've tried it and it doesn't work? If so, I'd suggest that you open a bug report and attach a sample capture so someone with some free time can take a look.
answered 23 Jul '12, 06:57