WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts
GNU General Public License v3.0
2.7k stars 242 forks source link

Add rules for Microsoft Remote Access VPN (client and server) #142

Closed ekt0-syn closed 1 year ago

ekt0-syn commented 1 year ago

This PR adds 7 rules to detect connection activity on Microsoft Remote Access VPN on both client and server sides.

Reference: https://github.com/synacktiv/forensic-msvpn

alexkornitzer commented 1 year ago

LGTM, thanks for the PR.