Ask Your Question

Revision history [back]

SMB3 traffic decrypt

I am using the script from this article https://medium.com/maverislabs/decrypting-smb3-traffic-with-just-a-pcap-absolutely-maybe-712ed23ff6a2 to create a key, the password is known. Providing session id and a calculated key does not produce decrypted traffic when Windows to Windows is communicating. But does produce when smbclient is communicating with Windows. What can be the reason?