1 | initial version |
Dissecting OPC Classic, which as the OP has noted is based on DCERPC, is very difficult.
I would instead use something like the Matrikon OPC Sniffer that sits between the client and the server and dumps out logs of the OPC traffic that can be examined.