Skip to content

Commit

Permalink
Update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
peacekeeper0 authored Nov 27, 2024
1 parent 412ba9f commit 8cf4b0b
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,6 @@ Notable Features:

## Conditional Coloring.cfg
I have taken all of the artifacts from the SANS FOR500 (red) poster and converted them into conditional coloring rules. Applying the rules will cause the "Name" column for an artifact to be highlighted with roughly the same color as the poster. Additionally, the color pink is used to highlight and callout encrypted files in general since those are probably important. This config gives you over 100 rules which you can immediately use or disable individually if you find one that you don't like.

## Installation
If installing Conditional Coloring.cfg, go to Options -> Directory Browser -> "Store dir. browser settings in cases" and make sure it is unchecked. When XWF is not running, replace the included file (Tooltips.txt or Conditional Coloring.cfg) in the main XWF installation directory with the one from this repo. Launch XWF and enable the associated feature if it is not already turned on.

0 comments on commit 8cf4b0b

Please sign in to comment.