Releases: yarox24/EvtxHussar
Releases · yarox24/EvtxHussar
EvtxHussar v1.8
- New function: Chart generation (Event frequency distribution) - Live chart demo
- Chart generation note: It' assumed that *.evtx files in the same directory got the "same" hostname (e.g. based on newest Security.evtx log)
- Remove a panic() from lot of a code. Replaced with error message. Related to issue: #6
EvtxHussar v1.7
- Added SMB maps (SMB_ClientDestinations, SMB_ServerAccessAudit, SMB_ServerModifications)
- Added 4 Event ID's to Accounts_UserRelatedOperations_Security
- Added Event ID 1029 to RDP_TerminalServices_RDPClient_Operational
EvtxHussar v1.6b
- Added XOR encryption flag (--scriptblockxor) for reconstructed PowerShell scriptblocks (to prevent their deletion by AV)
- Added --includeonly, --excludeonly to better control which maps will be filtered from execution (as a preparation for Velociraptor plugin)
- Removed map: ActiveDirectory Computer Accounts
- Added map: Audit - Policy change
- Added map: Boot up/Restart/Shutdown
- Enhancing GroupMembership field by SID List names
- Added append_to_field() function
- Added keywords to support better Security Events (Success/Failure)
Version 1.6b changes:
- Minor fix related to --scriptblockxor option
EvtxHussar v1.5
- Support for Windows Defender AV logs
EvtxHussar v1.4
- Support for RDP logs
- Support for Windows Firewall logs
- Introducing Logic engine (for. example event 4624 with Logon Type 10 is appended to RDP log)
- Support for Symantec Network Protection logs
- Minor fix for loading .evtx files
EvtxHussar v1.3
Changes:
- Support for WinRM logs
- Better handling of dirty .evtx files
- Fixed Linux powershell scriptblocks directory creation permissions
- OrderedDict case-insensitive errors
EvtxHussar v1.2
Changes:
- Support for logon related events
- Excel now split output to multiple files when exceeding million of rows
- Minor time changes (Appending zeros)
EvtxHussar v1.1a
Changed name convention of Windows executable
EvtxHussar v1.1
Changelog:
Fixed wrong EventTime present in all events.