Back to Display Filter Reference
| Field name | Type | Description | Versions |
|---|---|---|---|
| kerberos.addr_ip | IPv4 address | IP Address | 1.0.0 to 1.6.5 |
| kerberos.addr_ipv6 | IPv6 address | IPv6 Address | 1.2.0 to 1.6.5 |
| kerberos.addr_nb | Character string | NetBIOS Address | 1.0.0 to 1.6.5 |
| kerberos.addr_type | Unsigned integer, 4 bytes | Addr-type | 1.0.0 to 1.6.5 |
| kerberos.adtype | Unsigned integer, 4 bytes | Type | 1.0.0 to 1.6.5 |
| kerberos.advalue | Sequence of bytes | Data | 1.0.0 to 1.6.5 |
| kerberos.apoptions | Sequence of bytes | APOptions | 1.0.0 to 1.6.5 |
| kerberos.apoptions.mutual_required | Boolean | Mutual required | 1.0.0 to 1.6.5 |
| kerberos.apoptions.reserved | Boolean | reserved | 1.4.0 to 1.6.5 |
| kerberos.apoptions.use_session_key | Boolean | Use Session Key | 1.0.0 to 1.6.5 |
| kerberos.aprep.data | Sequence of bytes | enc-part | 1.0.0 to 1.6.5 |
| kerberos.aprep.enc_part | Label | enc-part | 1.0.0 to 1.6.5 |
| kerberos.Authenticator | Label | Authenticator | 1.0.0 to 1.6.5 |
| kerberos.authenticator.data | Sequence of bytes | Authenticator data | 1.0.0 to 1.6.5 |
| kerberos.authenticator_vno | Unsigned integer, 4 bytes | Authenticator vno | 1.0.0 to 1.6.5 |
| kerberos.AuthorizationData | Label | AuthorizationData | 1.0.0 to 1.6.5 |
| kerberos.authtime | Character string | Authtime | 1.0.0 to 1.6.5 |
| kerberos.Checksum | Label | Checksum | 1.0.0 to 1.6.5 |
| kerberos.checksum.checksum | Sequence of bytes | checksum | 1.0.0 to 1.6.5 |
| kerberos.checksum.type | Unsigned integer, 4 bytes | Type | 1.0.0 to 1.6.5 |
| kerberos.cname | Label | Client Name | 1.0.0 to 1.6.5 |
| kerberos.crealm | Character string | Client Realm | 1.0.0 to 1.6.5 |
| kerberos.cred_body | Label | CRED_BODY | 1.0.0 to 1.6.5 |
| kerberos.ctime | Character string | ctime | 1.0.0 to 1.6.5 |
| kerberos.cusec | Unsigned integer, 4 bytes | cusec | 1.0.0 to 1.6.5 |
| kerberos.e_checksum | Label | e-checksum | 1.0.0 to 1.6.5 |
| kerberos.e_data | Label | e-data | 1.0.0 to 1.6.5 |
| kerberos.e_text | Character string | e-text | 1.0.0 to 1.6.5 |
| kerberos.enc_authorization_data.encrypted | Sequence of bytes | enc-authorization-data | 1.2.0 to 1.6.5 |
| kerberos.enc_priv | Label | Encrypted PRIV | 1.0.0 to 1.6.5 |
| kerberos.EncAPRepPart | Label | EncAPRepPart | 1.0.0 to 1.6.5 |
| kerberos.EncKDCRepPart | Label | EncKDCRepPart | 1.0.0 to 1.6.5 |
| kerberos.EncKrbCredPart | Label | EncKrbCredPart | 1.0.0 to 1.6.5 |
| kerberos.EncKrbCredPart.encrypted | Sequence of bytes | enc EncKrbCredPart | 1.0.0 to 1.6.5 |
| kerberos.EncKrbPrivPart | Label | EncKrbPrivPart | 1.0.0 to 1.6.5 |
| kerberos.encrypted_cred | Label | EncKrbCredPart | 1.0.0 to 1.6.5 |
| kerberos.EncTicketPart | Label | EncTicketPart | 1.0.0 to 1.6.5 |
| kerberos.endtime | Character string | End time | 1.0.0 to 1.6.5 |
| kerberos.error_code | Unsigned integer, 4 bytes | error_code | 1.0.0 to 1.6.5 |
| kerberos.etype | Signed integer, 4 bytes | Encryption type | 1.0.0 to 1.6.5 |
| kerberos.etype_info.s2kparams | Sequence of bytes | Salt | 1.0.0 to 1.6.5 |
| kerberos.etype_info.salt | Sequence of bytes | Salt | 1.0.0 to 1.6.5 |
| kerberos.etype_info2.salt | Sequence of bytes | Salt | 1.0.0 to 1.6.5 |
| kerberos.etypes | Label | Encryption Types | 1.0.0 to 1.6.5 |
| kerberos.from | Character string | from | 1.0.0 to 1.6.5 |
| kerberos.gssapi.bdn | Sequence of bytes | Bnd | 1.0.0 to 1.6.5 |
| kerberos.gssapi.checksum.flags.conf | Boolean | Conf | 1.0.0 to 1.6.5 |
| kerberos.gssapi.checksum.flags.dce-style | Boolean | DCE-style | 1.0.0 to 1.6.5 |
| kerberos.gssapi.checksum.flags.deleg | Boolean | Deleg | 1.0.0 to 1.6.5 |
| kerberos.gssapi.checksum.flags.integ | Boolean | Integ | 1.0.0 to 1.6.5 |
| kerberos.gssapi.checksum.flags.mutual | Boolean | Mutual | 1.0.0 to 1.6.5 |
| kerberos.gssapi.checksum.flags.replay | Boolean | Replay | 1.0.0 to 1.6.5 |
| kerberos.gssapi.checksum.flags.sequence | Boolean | Sequence | 1.0.0 to 1.6.5 |
| kerberos.gssapi.dlglen | Unsigned integer, 2 bytes | DlgLen | 1.0.0 to 1.6.5 |
| kerberos.gssapi.dlgopt | Unsigned integer, 2 bytes | DlgOpt | 1.0.0 to 1.6.5 |
| kerberos.gssapi.len | Unsigned integer, 4 bytes | Length | 1.0.0 to 1.6.5 |
| kerberos.hostaddress | Label | HostAddress | 1.0.0 to 1.6.5 |
| kerberos.hostaddresses | Label | HostAddresses | 1.0.0 to 1.6.5 |
| kerberos.if_relevant | Label | IF_RELEVANT | 1.0.0 to 1.6.5 |
| kerberos.IF_RELEVANT.type | Unsigned integer, 4 bytes | Type | 1.0.0 to 1.6.5 |
| kerberos.IF_RELEVANT.value | Sequence of bytes | Data | 1.0.0 to 1.6.5 |
| kerberos.kdc_req_body | Label | KDC_REQ_BODY | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions | Sequence of bytes | KDCOptions | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.allow_postdate | Boolean | Allow Postdate | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.canonicalize | Boolean | Canonicalize | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.constrained_delegation | Boolean | Constrained Delegation | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.disable_transited_check | Boolean | Disable Transited Check | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.enc_tkt_in_skey | Boolean | Enc-Tkt-in-Skey | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.forwardable | Boolean | Forwardable | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.forwarded | Boolean | Forwarded | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.opt_hardware_auth | Boolean | Opt HW Auth | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.postdated | Boolean | Postdated | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.proxiable | Boolean | Proxiable | 1.2.0 to 1.6.5 |
| kerberos.kdcoptions.proxy | Boolean | Proxy | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.proxyable | Boolean | Proxyable | 1.0.0 to 1.0.16 |
| kerberos.kdcoptions.renew | Boolean | Renew | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.renewable | Boolean | Renewable | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.renewable_ok | Boolean | Renewable OK | 1.0.0 to 1.6.5 |
| kerberos.kdcoptions.validate | Boolean | Validate | 1.0.0 to 1.6.5 |
| kerberos.kdcrep.data | Sequence of bytes | enc-part | 1.0.0 to 1.6.5 |
| kerberos.kdcrep.enc_part | Label | enc-part | 1.0.0 to 1.6.5 |
| kerberos.key | Label | key | 1.0.0 to 1.6.5 |
| kerberos.key_expiration | Character string | Key Expiration | 1.0.0 to 1.6.5 |
| kerberos.keytype | Unsigned integer, 4 bytes | Key type | 1.0.0 to 1.6.5 |
| kerberos.keyvalue | Sequence of bytes | Key value | 1.0.0 to 1.6.5 |
| kerberos.KrbCredInfo | Label | KrbCredInfo | 1.0.0 to 1.6.5 |
| kerberos.KrbCredInfos | Label | Sequence of KrbCredInfo | 1.0.0 to 1.6.5 |
| kerberos.kvno | Unsigned integer, 4 bytes | Kvno | 1.0.0 to 1.6.5 |
| kerberos.LastReq | Label | LastReq | 1.0.0 to 1.6.5 |
| kerberos.LastReqs | Label | LastReqs | 1.0.0 to 1.6.5 |
| kerberos.lr_time | Character string | Lr-time | 1.0.0 to 1.6.5 |
| kerberos.lr_type | Unsigned integer, 4 bytes | Lr-type | 1.0.0 to 1.6.5 |
| kerberos.midl.fill_bytes | Unsigned integer, 4 bytes | Fill bytes | 1.0.0 to 1.6.5 |
| kerberos.midl.hdr_len | Unsigned integer, 2 bytes | HDR Length | 1.0.0 to 1.6.5 |
| kerberos.midl.version | Unsigned integer, 1 byte | Version | 1.0.0 to 1.6.5 |
| kerberos.midl_blob_len | Unsigned integer, 8 bytes | Blob Length | 1.0.0 to 1.6.5 |
| kerberos.msg.type | Unsigned integer, 4 bytes | MSG Type | 1.0.0 to 1.6.5 |
| kerberos.name_string | Character string | Name | 1.0.0 to 1.6.5 |
| kerberos.name_type | Signed integer, 4 bytes | Name-type | 1.0.0 to 1.6.5 |
| kerberos.nonce | Unsigned integer, 4 bytes | Nonce | 1.0.0 to 1.6.5 |
| kerberos.PA_ENC_TIMESTAMP.encrypted | Sequence of bytes | enc PA_ENC_TIMESTAMP | 1.0.0 to 1.6.5 |
| kerberos.pac.clientid | Date and time | ClientID | 1.0.0 to 1.6.5 |
| kerberos.pac.entries | Unsigned integer, 4 bytes | Num Entries | 1.0.0 to 1.6.5 |
| kerberos.pac.name | Character string | Name | 1.0.0 to 1.6.5 |
| kerberos.pac.namelen | Unsigned integer, 2 bytes | Name Length | 1.0.0 to 1.6.5 |
| kerberos.pac.offset | Unsigned integer, 4 bytes | Offset | 1.0.0 to 1.6.5 |
| kerberos.pac.signature.signature | Sequence of bytes | Signature | 1.0.0 to 1.6.5 |
| kerberos.pac.signature.type | Signed integer, 4 bytes | Type | 1.0.0 to 1.6.5 |
| kerberos.pac.size | Unsigned integer, 4 bytes | Size | 1.0.0 to 1.6.5 |
| kerberos.pac.type | Unsigned integer, 4 bytes | Type | 1.0.0 to 1.6.5 |
| kerberos.pac.upn.dns_len | Unsigned integer, 2 bytes | DNS Len | 1.2.0 to 1.6.5 |
| kerberos.pac.upn.dns_name | Character string | DNS Name | 1.2.0 to 1.6.5 |
| kerberos.pac.upn.dns_offset | Unsigned integer, 2 bytes | DNS Offset | 1.2.0 to 1.6.5 |
| kerberos.pac.upn.flags | Unsigned integer, 4 bytes | Flags | 1.2.0 to 1.6.5 |
| kerberos.pac.upn.upn_len | Unsigned integer, 2 bytes | UPN Len | 1.2.0 to 1.6.5 |
| kerberos.pac.upn.upn_name | Character string | UPN Name | 1.2.0 to 1.6.5 |
| kerberos.pac.upn.upn_offset | Unsigned integer, 2 bytes | UPN Offset | 1.2.0 to 1.6.5 |
| kerberos.pac.version | Unsigned integer, 4 bytes | Version | 1.0.0 to 1.6.5 |
| kerberos.PAC_CLIENT_INFO_TYPE | Sequence of bytes | PAC_CLIENT_INFO_TYPE | 1.0.0 to 1.6.5 |
| kerberos.PAC_CONSTRAINED_DELEGATION | Sequence of bytes | PAC_CONSTRAINED_DELEGATION | 1.0.0 to 1.6.5 |
| kerberos.PAC_CREDENTIAL_TYPE | Sequence of bytes | PAC_CREDENTIAL_TYPE | 1.0.0 to 1.6.5 |
| kerberos.PAC_LOGON_INFO | Sequence of bytes | PAC_LOGON_INFO | 1.0.0 to 1.6.5 |
| kerberos.PAC_PRIVSVR_CHECKSUM | Sequence of bytes | PAC_PRIVSVR_CHECKSUM | 1.0.0 to 1.6.5 |
| kerberos.pac_request.flag | Boolean | PAC Request | 1.0.0 to 1.6.5 |
| kerberos.PAC_SERVER_CHECKSUM | Sequence of bytes | PAC_SERVER_CHECKSUM | 1.0.0 to 1.6.5 |
| kerberos.PAC_UPN_DNS_INFO | Sequence of bytes | UPN_DNS_INFO | 1.2.0 to 1.6.5 |
| kerberos.padata | Label | padata | 1.0.0 to 1.6.5 |
| kerberos.padata.type | Signed integer, 4 bytes | Type | 1.0.0 to 1.6.5 |
| kerberos.padata.value | Sequence of bytes | Value | 1.0.0 to 1.6.5 |
| kerberos.patimestamp | Character string | patimestamp | 1.0.0 to 1.6.5 |
| kerberos.pausec | Unsigned integer, 4 bytes | pausec | 1.0.0 to 1.6.5 |
| kerberos.pname | Label | Delegated Principal Name | 1.0.0 to 1.6.5 |
| kerberos.prealm | Character string | Delegated Principal Realm | 1.0.0 to 1.6.5 |
| kerberos.priv_body | Label | PRIV_BODY | 1.0.0 to 1.6.5 |
| kerberos.PRIV_BODY.user_data | Sequence of bytes | User Data | 1.0.0 to 1.6.5 |
| kerberos.provsrv_location | Character string | PROVSRV Location | 1.0.0 to 1.6.5 |
| kerberos.pvno | Unsigned integer, 4 bytes | Pvno | 1.0.0 to 1.6.5 |
| kerberos.r_address | Label | R-Address | 1.0.0 to 1.6.5 |
| kerberos.realm | Character string | Realm | 1.0.0 to 1.6.5 |
| kerberos.renenw_till | Character string | Renew-till | 1.0.0 to 1.6.5 |
| kerberos.rm.length | Unsigned integer, 4 bytes | Record Length | 1.0.0 to 1.6.5 |
| kerberos.rm.reserved | Boolean | Reserved | 1.0.0 to 1.6.5 |
| kerberos.rtime | Character string | rtime | 1.0.0 to 1.6.5 |
| kerberos.s4u2self.auth | Character string | S4U2Self Auth | 1.0.0 to 1.6.5 |
| kerberos.s_address | Label | S-Address | 1.0.0 to 1.6.5 |
| kerberos.SAFE_BODY.timestamp | Character string | Timestamp | 1.0.0 to 1.6.5 |
| kerberos.SAFE_BODY.usec | Unsigned integer, 4 bytes | usec | 1.0.0 to 1.6.5 |
| kerberos.SAFE_BODY.user_data | Sequence of bytes | User Data | 1.0.0 to 1.6.5 |
| kerberos.seq_number | Unsigned integer, 4 bytes | Seq Number | 1.0.0 to 1.6.5 |
| kerberos.smb.nt_status | Unsigned integer, 4 bytes | NT Status | 1.0.0 to 1.6.5 |
| kerberos.smb.unknown | Unsigned integer, 4 bytes | Unknown | 1.0.0 to 1.6.5 |
| kerberos.sname | Label | Server Name | 1.0.0 to 1.6.5 |
| kerberos.sq.tickets | Label | Tickets | 1.0.0 to 1.6.5 |
| kerberos.srealm | Character string | SRealm | 1.0.0 to 1.6.5 |
| kerberos.starttime | Character string | Start time | 1.0.0 to 1.6.5 |
| kerberos.stime | Character string | stime | 1.0.0 to 1.6.5 |
| kerberos.subkey | Label | Subkey | 1.0.0 to 1.6.5 |
| kerberos.susec | Unsigned integer, 4 bytes | susec | 1.0.0 to 1.6.5 |
| kerberos.ticket | Label | Ticket | 1.0.0 to 1.6.5 |
| kerberos.ticket.data | Sequence of bytes | enc-part | 1.0.0 to 1.6.5 |
| kerberos.ticket.enc_part | Label | enc-part | 1.0.0 to 1.6.5 |
| kerberos.ticketflags | Label | Ticket Flags | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.allow_postdate | Boolean | Allow Postdate | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.forwardable | Boolean | Forwardable | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.forwarded | Boolean | Forwarded | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.hw_auth | Boolean | HW-Auth | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.initial | Boolean | Initial | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.invalid | Boolean | Invalid | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.ok_as_delegate | Boolean | Ok As Delegate | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.postdated | Boolean | Postdated | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.pre_auth | Boolean | Pre-Auth | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.proxiable | Boolean | Proxiable | 1.2.0 to 1.6.5 |
| kerberos.ticketflags.proxy | Boolean | Proxy | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.proxyable | Boolean | Proxyable | 1.0.0 to 1.0.16 |
| kerberos.ticketflags.renewable | Boolean | Renewable | 1.0.0 to 1.6.5 |
| kerberos.ticketflags.transited_policy_checked | Boolean | Transited Policy Checked | 1.0.0 to 1.6.5 |
| kerberos.till | Character string | till | 1.0.0 to 1.6.5 |
| kerberos.tkt_vno | Unsigned integer, 4 bytes | Tkt-vno | 1.0.0 to 1.6.5 |
| kerberos.transited.contents | Sequence of bytes | Contents | 1.0.0 to 1.6.5 |
| kerberos.transited.type | Unsigned integer, 4 bytes | Type | 1.0.0 to 1.6.5 |
| kerberos.TransitedEncoding | Label | TransitedEncoding | 1.0.0 to 1.6.5 |