This is our old Q&A Site. Please post any new questions and answers at

Below is the SMB2 header for a successful Create from a client to a server. The next packet in the trace says the Create was successful. How do I figure out what file was created and where? There is nothing in the Filename and nothing under the Tree Id.

alt text

asked 18 Aug '14, 10:13

Tom%20Fury's gravatar image

Tom Fury
accept rate: 0%

Hi Tom,

I've often seen this in SMB2 traces. I think the answer is that the client is opening the root directory relative to the current share. The share is identified by the Tree ID value, and if you've captured the connection to the share you'll see the Tree Connect request which will contain the share name.

I've noticed a typical scenario is the client opens the directory with a Create Request (Disposition - Open), issues a Find Request looking for a particular file (sometimes with wildcard values) and then you see a Close Request for the directory.

Some information that may help:

Best regards...Paul

permanent link

answered 19 Aug '14, 13:05

PaulOfford's gravatar image

accept rate: 11%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 18 Aug '14, 10:13

question was seen: 3,620 times

last updated: 19 Aug '14, 13:05

p​o​w​e​r​e​d by O​S​Q​A