add sysmon

This commit is contained in:
siamease
2020-10-02 00:14:33 +09:00
parent 42f8483485
commit fa9f3813ae
3 changed files with 4 additions and 4 deletions

View File

@@ -3,8 +3,8 @@ extern crate quick_xml;
use crate::detections::application;
use crate::detections::common;
use crate::detections::security;
use crate::detections::system;
use crate::detections::sysmon;
use crate::detections::system;
use crate::models::event;
use evtx::EvtxParser;
use quick_xml::de::DeError;

View File

@@ -2,5 +2,5 @@ mod application;
mod common;
pub mod detection;
mod security;
mod system;
mod sysmon;
mod system;

View File

@@ -24,10 +24,10 @@ impl Sysmon {
fn sysmon_event_1(&mut self, event_data: HashMap<String, String>) {
println!("Message : Sysmon event 1");
if let Some(_image) = event_data.get("Image") {
println!("_image : {}",_image);
println!("_image : {}", _image);
}
if let Some(_command_line) = event_data.get("CommandLine") {
println!("_command_line : {}",_command_line);
println!("_command_line : {}", _command_line);
}
}