sans-blue-team / DeepBlueCLI

GNU General Public License v3.0
2.16k stars 352 forks source link

DeepWhite-collector #19

Open GlennGuillot opened 3 years ago

GlennGuillot commented 3 years ago

Is there an issues getting this to work on Windows 10 (2004) with the latest version of Sysmon 12.0.3?

I get the error when running the powerShell script DeepWhite-collector: Out-Host : A positional parameter cannot be found that accepts argument 'No SHA256 hash found. Ensure Sysmon is creatin g SHA256 hashes'. At DeepWhite-collector.ps1:36 char:9

If I look in the Eventviewer, I can see the sha256 hashes for events 1 and 7 are present