Skip to content

uberAgent 7.2 support#34

Open
Endecs wants to merge 29 commits intodevelopfrom
feature/B952-OriginalFileName
Open

uberAgent 7.2 support#34
Endecs wants to merge 29 commits intodevelopfrom
feature/B952-OriginalFileName

Conversation

@Endecs
Copy link
Copy Markdown
Contributor

@Endecs Endecs commented Jul 8, 2024

  • Added uberAgent 7.2 to version selection
  • Stage 1 for OriginalFileName support
    • Stage 1: OriginalFileName works differently to Process.Name, this will be updated in the next uberAgent versions, until then we have decided to use OriginalFileName with Process.Name.
  • Using Reg.TargetObject from version 7.2 for Sysmon TargetObject.
  • The converter can now handle the same attributes for different versions.
  • Simplified and fixed some errors in query builder

@Endecs Endecs requested a review from PhBrz July 8, 2024 16:53
Comment thread README.md
PhBrz added 3 commits July 18, 2024 17:05
fixed relation for same attributes - this are always connected with or.

fixed excludes any and excludes and excludes all
Comment thread vl.Sysmon.Converter/Domain/ConvertEntity.cs Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants