I would like to know if you possible to add new feature in FastFind to find special event (ID, content, ...).
E.G. :
search mimikaz in xml_string
wannamine (less file malware, content in memory by wmi subscribtion => OBJECTS.DATA is not readable, you can to find IOC in evtx [powershell, WMI, ...])
Hi,
I would like to know if you possible to add new feature in FastFind to find special event (ID, content, ...).
E.G. :
I think there are different ways to do it:
If you choose the second case, the configuration file could be:
Output result can be like this:
If you choose the last case, the configuration file could be:
Output result can be like this:
Thank for you help!