Commit Graph

101 Commits

Author SHA1 Message Date
Tanaka Zakku
717b214917 Downloads typo fix 2022-07-24 11:22:18 +09:00
Tanaka Zakku
966994a755 1.4.2 finalization 2022-07-23 23:01:58 +09:00
Tanaka Zakku
3312572bb8 update readme EvtxFile 2022-07-20 03:56:08 +09:00
Tanaka Zakku
411ebcadfb readme update 2022-07-01 07:27:46 +09:00
DastInDark
19da792271 updated document #355 2022-06-30 22:42:08 +09:00
Tanaka Zakku
70c6f28556 update changelog and readme 1.4.1 2022-06-30 12:09:00 +09:00
Tanaka Zakku
ffc2c35b7b finalize 1.4.1 2022-06-30 08:45:25 +09:00
DastInDark
70f03887e8 Merge branch 'main' into 606-print-all-field-info-when-no-details-are-defined 2022-06-29 22:31:38 +09:00
Tanaka Zakku
5da0c6982b delete unneeded files 2022-06-29 22:10:55 +09:00
DastInDark
59f79161be updated readme #606 2022-06-29 20:52:15 +09:00
Tanaka Zakku
dd28d27afe updates 2022-06-29 10:17:23 +09:00
DustInDark
235c405879 updated readme #608 2022-06-29 00:40:27 +09:00
DustInDark
848cb710b0 updated help menu #608 2022-06-29 00:40:07 +09:00
Tanaka Zakku
5eba217d65 readme link fixes 2022-06-26 20:49:56 +09:00
Tanaka Zakku
f20cdf66f6 update readme <[ ]> 2022-06-26 18:29:14 +09:00
Tanaka Zakku
767897f7ef readmeupdate 2022-06-26 09:59:31 +09:00
Tanaka Zakku
77945e5562 v1.4.0 release 2022-06-26 08:07:22 +09:00
DustInDark
f4dea799bc Merge branch 'main' into 592-config-flag-seems-to-be-ignored 2022-06-25 21:57:01 +09:00
DustInDark
7937ea41d5 Merge branch 'main' into 596-new-feature-exclude-status 2022-06-24 23:43:44 +09:00
DustInDark
8c377b2195 update readme 2022-06-23 21:34:24 +09:00
Tanaka Zakku
4d00bbf06d readme and changelog update 2022-06-23 07:36:41 +09:00
Tanaka Zakku
965e2bb91c update changelog and readme text 2022-06-21 16:30:24 +09:00
DustInDark
d24a3e3b58 updated readme #596 2022-06-21 15:12:32 +09:00
DustInDark
b4ef082525 Merge pull request #594 from Yamato-Security/586-evtx-files-with-different-extension-option
evtx files with different extension option( --add-file-extentions)
2022-06-21 12:09:41 +09:00
Tanaka Zakku
e37371a077 update readme and option name 2022-06-21 11:00:32 +09:00
Tanaka Zakku
8b532af5c6 readme and changelog update 2022-06-20 22:32:52 +09:00
DustInDark
c413bd1872 updated readme #586 2022-06-20 20:24:35 +09:00
DustInDark
4b2c047f95 fixed ProviderName typo #359 2022-06-20 13:55:09 +09:00
DustInDark
158a1e34ed fixed document #359 2022-06-20 13:48:44 +09:00
DustInDark
6ccda3add8 updated readme #359 2022-06-20 00:06:07 +09:00
DustInDark
acfc3437ba removed correlations 2022-06-19 11:44:47 +09:00
Tanaka Zakku
9f32edb7bf readme update 2022-06-19 10:13:56 +09:00
Tanaka Zakku
47c0eee38c updated cargo, readme, usage 2022-06-19 10:08:59 +09:00
DustInDark
ac246522d4 updated usage in readme 2022-06-17 19:04:55 +09:00
DustInDark
334c401cda Merge branch 'main' into clap_update_v3 2022-06-14 22:53:52 +09:00
Tanaka Zakku
ce51728070 v1.3.2 2022-06-13 08:55:01 +09:00
DustInDark
acf81b1d64 updated readme #413 2022-06-13 02:49:54 +09:00
Tanaka Zakku
04b41e7a5d update changelog and readme 2022-06-11 14:47:55 +09:00
DustInDark
e6a77aee90 updated readme #579 2022-06-11 05:05:09 +09:00
DustInDark
0ca89509b9 updated readme #579 2022-06-10 16:51:26 +09:00
Tanaka Zakku
35f4a92f21 updated readme and usage examples 2022-06-09 09:20:49 +09:00
DustInDark
2e45fa9fb8 fixed rfc-3339 output format #574 2022-06-08 18:58:38 +09:00
DustInDark
863d443b5c added three new time format option in readme #574 2022-06-08 18:57:51 +09:00
DustInDark
d00737c033 add view event frequency timeline option (#567)
* added option visual-timeline option #566

* updated readme #566

* updated changelog #566

* updated rules

* cargo fmt

* change --visual-timeline to --visualize-timeline

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-06-05 17:41:08 +09:00
Yamato Security
bdd841f872 V1.3.0 release finalization (#564)
* readme, cargo, usages  update

* readme update
2022-06-04 06:53:40 +09:00
DustInDark
9e1fabb21e display computers with most alerts (#558)
* added top3 alert by level and computer #557

* cargo fmt

* updated changelog #557

* updated readme #557

* added output when one computer name in level. #557

* updated screenshot

* updated rules

* add SOF-ELK link

* readme update

* readme update

* cargo fmt

* change display num from 3 to 5 #557

* excluded count when computer name is "-" in event and fixed output #557

- removed warn output.

- changed output when count is 0.

* cargo fmt

* changed computer name summary to filter unique computer name and rule path pair #557

* cargo fmt

* readme update change order of output

* changelog update

* fixed crash bug when level is not valid #560 #557

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-06-03 12:01:14 +09:00
DustInDark
2dcf960d51 display default channel name if not defined (#555)
* displayed other channel data in Channel column #553

* updated changelog #553

* updated changelog

* readme and channel abbreviataions update

* changelog update

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-06-01 13:01:14 +09:00
DustInDark
7a7afe732c most detections summary by date (#551)
* added Date with most detections by level #550

* cargo fmt

* updated changelog #550

* updated readme #550

* removed  most undefined detections date in summary #550

* cargo fmt

* add space after level tuning

* changed undefined rule detection count to no show #550

* cargo fmt

* readme update

* channel abb update

* channel abb update

* readme update

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-05-31 22:29:51 +09:00
DustInDark
2653e87588 start timeline and end timeline do not work (#547)
* fixed dont work start-timeline and end-timeline #546

* fixed condition

* added changelog #546

* changelog update

* changed stop analysis when start-timeline and end-timeline happend parse error #546

* cargo fmt

* fixed alert message

* fixed lack of timestamp convert

* cargo fmt

* readme/usage update

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-05-28 10:07:39 +09:00
DustInDark
a17d0d4e37 display EventRecordID (#549)
* added -R --display-record-id #548

* fixed test data #548

* cargo fmt

* added describe of -R --display-record-id option to README #548

* updated changelog #548

* readme update

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-05-27 22:19:40 +09:00