[Feature Request/SysmonShell] - Support for Sysmon Schema 3.40
woifi opened this issue · 3 comments
woifi commented
Hi,
your work looks great but it seems that it does not support the current sysmon schema 3.40. I was wondering if you plan to release an updated version that would support 3.40?
Thanks,
woifi
nshalabi commented
Thanks,
I will check it, since I actually did update Sysmon Shell to include the new schema (with WMI events), Sysmon View is not yet updated though, but working on it.
Regards, Nader
Get Outlook for Android<https://aka.ms/ghei36>
From: woifi
Sent: Tuesday, November 14, 8:29 PM
Subject: [nshalabi/SysmonTools] [Feature Request/SysmonShell] - Support for Sysmon Schema 3.40 (#3)
To: nshalabi/SysmonTools
Cc: Subscribed
Hi,
your work looks great but it seems that it does not support the current sysmon schema 3.40. I was wondering if you plan to release an updated version that would support 3.40?
Thanks,
woifi
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnshalabi%2FSysmonTools%2Fissues%2F3&data=02%7C01%7Cnader_shalabi%40hotmail.com%7C129d12ea44b947f475ec08d52b7cea34%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636462737851738794&sdata=PDmt8U29Od4G0znDwCG%2Fd6Le78%2FX5M1equqBkjcWS7A%3D&reserved=0>, or mute the thread<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FAIVASWS4r9TmszzaMDqG5X30Ohfjq8aBks5s2b_3gaJpZM4Qdnhv&data=02%7C01%7Cnader_shalabi%40hotmail.com%7C129d12ea44b947f475ec08d52b7cea34%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636462737851738794&sdata=cY%2BxO23iN4BlZwwXP1MZJp4nnmhgA4LB8wEp2gCKdQ8%3D&reserved=0>.
nshalabi commented
Hi woifi,
Can you please elaborate more on "it seems that it does not support the current sysmon schema 3.40"? Where did you spot that exactly?
Much appreciated
nshalabi commented
The tool is updated to support the latest schema, thank you for reporting.