This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

capture windows named pipe traffic such as \pipe\lsarpc, \pipe\netlogon, \pipe\samr

0

I have a server that has named pipe such as \pipe\lsarpc, \pipe\netlogon, \pipe\samr,

I need to decommission the server and wanted to know if any clients are still connecting thru those named pipes and which clients are connecting via it and doing what.

And also to see if any clients are still be authenticated thru that server.

Appreciated very much for any assistance.

asked 18 Feb '14, 17:48

rm2014's gravatar image

rm2014
1111
accept rate: 0%