Skip to content

Extract fields from EVTX events #1

@berggren

Description

@berggren

In order to model nodes and edges for graph creation it would be very handy to have an attribute container with the event fields extracted.

One use-case is to track lateral movement in a windows environment using eventID 4624, using these fields:

  • IpAddress
  • Computer
  • TargetUserName
  • LogonType
  • WorkstationName
  • TargetDomain

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions