OTRF / OSSEM

Open Source Security Events Metadata (OSSEM)
MIT License
1.23k stars 214 forks source link

PowerShell 4104 matching HELK #45

Open neu5ron opened 5 years ago

neu5ron commented 5 years ago

PowerShell 4104 needs to match HELK. Few fields that we parse from here that are not in here.

Also I believe powershell_Path should be powershell_path

@Cyb3rWard0g probably going to need your input on this, since the original parser you had some modifications - so just wanted to get your final on it.