Neo23x0 / Loki

Loki - Simple IOC and YARA Scanner
https://www.nextron-systems.com/compare-our-scanners/
GNU General Public License v3.0
3.4k stars 583 forks source link

CSV output error - no double quoted quotes #194

Open eduardomcm opened 3 years ago

eduardomcm commented 3 years ago

The CSV output is not being properly parsed by other tools as quotes are not escaped (not double quoted).

Would it be possible to fix this? And perhaps add a json output instead of CSV?

20210914T18:02:40Z,WIN10PRO,INFO,ProcessScan,Scanning Process PID: 80 NAME: WUDFHost.exe OWNER: LOCAL SERVICE CMD: "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-07a33b14-b888-4e0a-8362-1371616aaeed -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-4fe88eee-76b2-42df-856c-84eaff23e0b1 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-8e923d53-a970-47ef-ae13-2f36c9ae1c52 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-e5419aa0-af8d-4645-82f6-c96aa01a6ca9 -LifetimeId:434f2d16-9acc-4d35-b2f4-f2bcf96d0937 -DeviceGroupId: -HostArg:0 PATH: C:\Windows\System32\WUDFHost.exe

Neo23x0 commented 3 years ago

I'm on vacation right now. I can fix the CSV output when I'm back in 2 weeks but I wouldn't add JSON output. We already have that in THOR and the free THOR Lite. If you don't have the requirement to use only open source software, I'd recommend using THOR Lite. Please let me know if that helped.

https://www.nextron-systems.com/thor-lite/