Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add ability to parse OriginalFilename #350

Open
theflakes opened this issue Dec 23, 2022 · 2 comments
Open

add ability to parse OriginalFilename #350

theflakes opened this issue Dec 23, 2022 · 2 comments

Comments

@theflakes
Copy link

MS doc: https://learn.microsoft.com/en-us/windows/win32/menurc/string-str?redirectedfrom=MSDN
Yara rule support for field: https://yara.readthedocs.io/en/v3.2.0/modules/pe.html

This is a useful field in threat hunting and forensics in general.

thanks

@m4b
Copy link
Owner

m4b commented Jan 1, 2023

Seems reasonable to me, would you like to make a PR adding this? (ideally backwards compatible/non breaking) :)

@theflakes
Copy link
Author

I can try at some point but its beyond my capabilities unfortunately. When I get some more time, I'll keep digging into it. Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants