New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Relative file creation times for Process and DLL events #269
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔥
This looks good
"relative_file_creation_time": 48628704.4029488, | ||
"relative_file_name_modify_time": 48628704.4029488 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thank you 🎆
custom_schemas/custom_process.yml
Outdated
- name: Ext.relative_file_creation_time | ||
level: custom | ||
type: double | ||
short: Number of seconds since the DLL's file was created |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is DLL
the correct terminology? Not executable or something. Not sure, just my copy-pasta spider sense is going off.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Well, it seems DLL
is used for all three types. So, perhaps these comments are just noise.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good catch. Thanks. Fixed: 476b668
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM FWIW
Change Summary
Add the EXE/DLL file's creation time, and file name modification time to process and DLL events, relative to the time of the event. They may be negative if the file's timestamps are in the future.
Release Target
8.4.0
Q/A
For mapping changes:
make
after making the schema changes, and committed all changes