Scanner NetBIOS Auxiliary Modules - Metasploit Unleashed An overview of the "nbname" and "nbname_probe" Scanner NetBIOS Auxiliary Modules of the Metasploit Framework. McAfee Support Community - NETBIOS-SS: Microsoft Windows netbios-ss-smb2-command == 0x0b ( unsigned ) This should help you analyse the PCAPs - but this is a low BTP signature, so it should not really be generating many FP. Maybe the alerts are TP (True positives, you should be able to match the regex on the description to the pcap) but with no security implication (i.e. the target host is patched

