Comments (6)
Yep, im using Powershell.
After following your last recommendation of changing ' for " it works!
Thanks a lot!
from chainsaw.
Hey @Richard1611,
The Key/Value pair is delimited with :
(#114). So it would be Event.System.EventID: 4104
from chainsaw.
Hi Alex, Thanks for your repply.
Now, when am doing chainsaw.exe search c:\Windows\System32\winevt\Logs -t Event.System.EventID: 4104 im getting this error:
[x] Specified event log path is invalid - 4104
I've tried to change the parameters orders as the help says, but it still not working.
Example:
chainsaw.exe search [OPTIONS] [PATTERN] [PATH] = chainsaw.exe search -t Event.System.EventID: 4624 c:\Windows\System32\winevt\Logs
from chainsaw.
Because there is a space there you will need to wrap it in quotes, something like this:
chainsaw.exe search c:\Windows\System32\winevt\Logs -t 'Event.System.EventID: 4104'
Also as EventID can sometimes be a string, IIRC, the safest way to do it is:
chainsaw.exe search c:\Windows\System32\winevt\Logs -t 'int(Event.System.EventID): 4104'
from chainsaw.
It stills giving me the same error:
[x] Specified event log path is invalid - 4104'
PD: Chainsaw version 2.6.0
from chainsaw.
Oh is this in Command Prompt or Powershell, you probably need to use "
instead if '
. I don't use Windows all that much.
from chainsaw.
Related Issues (20)
- Add timestamp format to help output HOT 2
- Deserialization error does't not show responsible file HOT 2
- Invalid Tau Key Pair error HOT 2
- Hunt with WEC/WEF HOT 2
- keyless identifiers cannot be converted HOT 3
- Check for potential I/0 error before processing HOT 1
- Erroneous Sigma Results using Hunt option HOT 7
- chainsaw project name collides with another rust project HOT 2
- v2.4+ seems to be unable to recognize Sigma alerts HOT 1
- Sophos Antivirus Rule Not Parsing Data Events With Same Key Name HOT 5
- Print warning when loading Sigma rules with keyless search identifiers HOT 6
- Missing Sigma Base64 Encoding? HOT 3
- -o flag not recognized HOT 2
- No executable HOT 1
- Looking for clarity for mft yaml 'filter' issue HOT 3
- [Feature Request] Support for "contains", "|" and "all" in both chainsaw and sigma rules HOT 4
- Search feature doesn't parse backslashes HOT 2
- Feature Request: Event Log ID / Sigma Summary HOT 1
- '--timezone' and '--local' option not working as intended HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from chainsaw.