Expand description
What the WebClient scanner collects: the WebDAV pipe name, the NTSTATUS
values we branch on, the per-host Outcome, and the classify that maps
one onto the other. Kept free of any SMB types so it unit-tests with no
Domain Controller (like LocalGroups-rs tests its NDR decoders).
Ported from https://github.com/g0h4n/IsWebClientRunning-rs for issue #72.
Modules§
- status
- NTSTATUS values we care about when opening the pipe.
Enums§
- Outcome
- Outcome of a single host probe, before it becomes a serialisable row.
Constants§
- PIPE_
NAME - SMB2 CREATE filename for the WebClient pipe (no leading separator; the tree is already IPC$). Its presence is the whole signal: a host running the WebClient (WebDAV) service registers this pipe, which makes it an ESC8 / coercion relay candidate.
- PIPE_
NAME_ DISPLAY - Human-facing full path, used in logs.