sans-blue-team / DeepBlueCLI

GNU General Public License v3.0
2.19k stars 355 forks source link

Nterl0k forwarded eventlog update #34

Open nterl0k opened 1 year ago

nterl0k commented 1 year ago

I've updated DeepBlue-CLI to be compatible with running it's detections over a Windows Event Collection (WEC) server's "Forwarded Event Log". Also added the "MachineName" field to all outputs to differentiate machine names.

A few minor logic changes were made to accomplish this, more testing may be needed but this worked in my production environment.

Warning banner Snipaste_2023-10-14_12-53-37

Local versus Forwarded Host Local Log Snipaste_2023-10-14_12-39-31

ForwardedLog Host Snipaste_2023-10-14_12-45-32