EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
280 stars 59 forks source link

suggested change as file name != executable name #189

Closed randomaccess3 closed 2 years ago

randomaccess3 commented 2 years ago

suggested change as in a large number of SMB failures the executable wouldn't be the interacted file the failure occurred on suggest moving it to a payload instead

Description

Please include a summary of the change and (if applicable) which issue is fixed.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

Thank you for your submission and for contributing to the DFIR community!