godaddy / procfilter

A YARA-integrated process denial framework for Windows
MIT License
395 stars 80 forks source link

Question: Logging Matched String From Yara Rule Matched #18

Open dfirence opened 4 years ago

dfirence commented 4 years ago

Greetings and Thank You For This AWESOME Tool!

Is it possible to obtain from the Windows Event Log Entry:

  1. the actual string that matched from the Yara Rule that is written?

In the screenshot below, I successfully am matching, but I would like to know how can the matched string be provided in the details.

Writing the Test Yara Rule

image


Successfully Matching in Windows Log

image

dfirence commented 4 years ago

Any update, please?