WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts
GNU General Public License v3.0
2.7k stars 242 forks source link

Rule for F-Secure Client Security 11 & 12 #158

Closed reece394 closed 8 months ago

reece394 commented 8 months ago

This should help with issue #26. I could only source version 11 and 12 of F-Secure for testing so I am unsure of the behavior of version 13. Attached are sample logs Fsecure.zip. I also added FSecure-FSecure-F-Secure DeepGuard based on #26 however I did not observe any events generated during testing on my end.

alexkornitzer commented 8 months ago

No worries we can always add 13 later if it pops up. Thanks again for getting so many native rules added.