markmckinnon / Autopsy-Plugins

Autopsy Python Plugins
332 stars 100 forks source link

Process_EVTX plugin: filter by "contains" operator #22

Closed beyefendi closed 2 years ago

beyefendi commented 4 years ago

It would be better to have a "contains" operator for filtering Evet Detail. For example, one needs to find event logs related to a specific process name.