Skip to content

Commit

Permalink
Merge pull request #956 from randomaccess3/master
Browse files Browse the repository at this point in the history
add block parser
  • Loading branch information
AndrewRathbun authored Aug 16, 2024
2 parents 4ed32ad + f7237d4 commit 7ae60a8
Showing 1 changed file with 15 additions and 0 deletions.
15 changes: 15 additions & 0 deletions Modules/Apps/block-parser-zipped.mkape
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
Description: Block Parser Zipped
Category: EventLogs
Author: Phill Moore
Version: 1.0
Id: cb817a29-bab0-4051-ac7d-7019d6e2ac65
BinaryUrl: https://github.com/randomaccess3/block-parser
ExportFormat: zip
Processors:
-
Executable: block-parser.exe
CommandLine: -o %destinationDirectory% -z "%sourceDirectory%\Windows\system32\winevt\logs\Microsoft-Windows-PowerShell%4Operational.evtx
ExportFormat: zip

# Documentation
# https://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.html

0 comments on commit 7ae60a8

Please sign in to comment.