You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I would like to know if you possible to add new feature in FastFind to find special event (ID, content, ...).
E.G. :
search mimikaz in xml_string
wannamine (less file malware, content in memory by wmi subscribtion => OBJECTS.DATA is not readable, you can to find IOC in evtx [powershell, WMI, ...])
Hi,
I would like to know if you possible to add new feature in FastFind to find special event (ID, content, ...).
E.G. :
I think there are different ways to do it:
If you choose the second case, the configuration file could be:
Output result can be like this:
If you choose the last case, the configuration file could be:
Output result can be like this:
Thank for you help!
The text was updated successfully, but these errors were encountered: