Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Process Report #5

Closed
mstarks01 opened this issue Feb 8, 2018 · 5 comments
Closed

Critical Process Report #5

mstarks01 opened this issue Feb 8, 2018 · 5 comments

Comments

@mstarks01
Copy link

The Critical Process Report appears to be expecting the executable names to be preceded by *\, but they are expanded simply as the exe name (i.e. cmd.exe). So, the report returns nothing as written.

@mstarks01
Copy link
Author

Same for Net Group, Localgroup report. Maybe others?

@MHaggis
Copy link
Owner

MHaggis commented Mar 8, 2018

Good catch! I'll get this fixed soon.

@MHaggis
Copy link
Owner

MHaggis commented Mar 21, 2018

If you have the ability, try this out with some data - https://github.com/MHaggis/sysmon-splunk-app/tree/App-v2
It's been working fine for me the last few days, including all the saved searches.

@MHaggis
Copy link
Owner

MHaggis commented Mar 21, 2018

I went ahead and merged. See Master Branch

@MHaggis MHaggis closed this as completed Mar 21, 2018
@mstarks01
Copy link
Author

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants