Skip to main content

Module types

Module types 

Source
Expand description

What the WebClient scanner collects: the WebDAV pipe name, the NTSTATUS values we branch on, the per-host Outcome, and the classify that maps one onto the other. Kept free of any SMB types so it unit-tests with no Domain Controller (like LocalGroups-rs tests its NDR decoders).

Ported from https://github.com/g0h4n/IsWebClientRunning-rs for issue #72.

Modules§

status
NTSTATUS values we care about when opening the pipe.

Enums§

Outcome
Outcome of a single host probe, before it becomes a serialisable row.

Constants§

PIPE_NAME
SMB2 CREATE filename for the WebClient pipe (no leading separator; the tree is already IPC$). Its presence is the whole signal: a host running the WebClient (WebDAV) service registers this pipe, which makes it an ESC8 / coercion relay candidate.
PIPE_NAME_DISPLAY
Human-facing full path, used in logs.

Functions§

classify
Map the NTSTATUS returned by the pipe CREATE into an Outcome. Isolated from the network so it unit-tests with no Domain Controller.