Wireshark-bugs: [Bug 5613] New: Enhancements to SID dissection
Date: Mon, 24 Jan 2011

           Summary: Enhancements to SID dissection
Enhancements to SID dissection:
• Well-known SIDs are mapped to names even if locally defined fields are
appended to them. This means that virtually all SIDs are now mapped. 

• Locally defined fields are marked as such. For example, an NT Service SID,
S-1-5-80, is displayed as “SID:
S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464  (NT
Service-<locally defined>)” 

• Added pseudo field “Well-known SID” to the tree and filter ‘nt.sid.wkwn’
which allows for well-known SIDs to be searched for (without having to use
"contains") regardless of the presence of locally defined fields.

• Added pseudo field “Domain” to the tree and filter 'nt.sid.domain' which
allows one to search for a domain embedded in a domain SID (e.g., (e.g.,
‘nt.sid.domain == "3305717449-1000208802-1772399307").

• In former versions (#5286), RIDs were only decoded for Domain SIDS (S-1-5-21)
but RIDs are now also decoded for well-known built-in 'local group' (S-1-5-32),
'authentication' (S-1-5-64), and 'mandatory level' (S-1-16) SIDs. It allows one
to search for the RID (e.g., nt.sid.rid==544) without having to specify the
entire SID in that all these RIDs are unique.

