Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Right click - Filter Target Path #6

Closed
theevilbit opened this issue Apr 17, 2023 · 3 comments
Closed

Right click - Filter Target Path #6

theevilbit opened this issue Apr 17, 2023 · 3 comments
Assignees
Labels
accepted-request This feature request has been initially accepted. We'll start digging. in-development The requested change is under development. rc-mac-feature-request

Comments

@theevilbit
Copy link

At a high level -- can you summarize your request?
Would be nice to be able to quickly filter events based on Target Paths, just like we have an option for Process Path filtering.

What is the current alternative solution?
Use muted paths in main settings, or export events and filter them manually.

Are there "In-the-Wild" threats or corresponding ATT&CK techniques that exist for which this telemetry would be helpful?
No, this only helps with general event filtering.

Anything else?
No

@Brandon7CC
Copy link
Contributor

This is one I'm happy the community brought in! Target path filtering is an additional option I think would be a relatively easy ask 😄

@Brandon7CC Brandon7CC added the accepted-request This feature request has been initially accepted. We'll start digging. label Apr 17, 2023
@AndrewMohawk
Copy link

Also would be nice to have filtering by the other columns available as well (Source process, Source Signing ID)

@Brandon7CC Brandon7CC added the in-development The requested change is under development. label May 19, 2023
@Brandon7CC
Copy link
Contributor

Implemented! See v1.0.4 -- thank you Csaba!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
accepted-request This feature request has been initially accepted. We'll start digging. in-development The requested change is under development. rc-mac-feature-request
Projects
None yet
Development

No branches or pull requests

3 participants