Analysis plugin: tagging

Joachim Metz edited this page Dec 3, 2017 · 5 revisions

Notes on how to use the tagging analysis plugin.

Creating the tagging file

A tagging-file.txt is an UTF-8 encoded text file that contains tagging definitions.

A tagging definition consists of:

TAG LABEL
  EVENT TAGGING EXPRESSION

For example:

task_schedule
  data_type is 'windows:evt:record' and source_name is 'Security' and event_identifier is 602
  data_type is 'windows:evtx:record' and source_name is 'Microsoft-Windows-Security-Auditing' and event_identifier is 4698

Running plaso

First run log2timeline to extract events:

log2timeline.py timeline.plaso image.raw

Next run psort to tag events:

psort.py --analysis tagging --tagging-file tagging-file.txt timeline.plaso

Also see

Clone this wiki locally
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.
Press h to open a hovercard with more details.