Search_Command that will search only network connections for hits on IP or part of/whole match of Domain/TLD
ceramicskate0 opened this issue · 1 comments
ceramicskate0 commented
Feature should be a command in the search config that can be IP or part of domain. Use sysmon by default or if it has a logname in search use search all feature to find if a log has contacted a domain.
Ideas:
possibly use network_connect command and if middle arg is not a number then do this search?
ceramicskate0 commented
use search multiple and eventid to do this