Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature extraction config for BITS and Terminal Services #2974

Merged
merged 11 commits into from
Dec 1, 2023

Conversation

roshanmaskey
Copy link
Collaborator

@roshanmaskey roshanmaskey commented Nov 5, 2023

Added Windows feature extraction configs for BITS client and Windows terminal services events.

Checks

  • All tests succeed.
  • Unit tests added.
  • e2e tests added.
  • Documentation updated.

Closing issues

Put closes #XXXX in your comment to auto-close the issue that your PR fixes
(if such).

@roshanmaskey roshanmaskey requested a review from jkppr November 5, 2023 23:10
Copy link
Collaborator

@jkppr jkppr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking good, thanks a lot for the additions. For two sources there are references missing. It would be great if you could add them to the config file. Thanks

data/winevt_features.yaml Outdated Show resolved Hide resolved
data/winevt_features.yaml Show resolved Hide resolved
data/winevt_features.yaml Outdated Show resolved Hide resolved
Copy link
Collaborator

@jkppr jkppr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added some references that I was able to find. However, there are still some missing especially around BITS-Clients events. Please take a look below.

data/winevt_features.yaml Show resolved Hide resolved
data/winevt_features.yaml Outdated Show resolved Hide resolved
data/winevt_features.yaml Outdated Show resolved Hide resolved
@jkppr jkppr added this to the Release: 20231206 milestone Dec 1, 2023
@jkppr jkppr merged commit 2ece8a5 into google:master Dec 1, 2023
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants