WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Incorrect hunt examples displayed

Cleako opened this issue · comments

Using the latest release (2.1.1), I found the example hunts displayed when executed without any arguments to be out of date and no longer working.

image

A working updated hunt example would be the following (executed using PowerShell):
.\chainsaw_x86_64-pc-windows-msvc.exe hunt .\EVTX-ATTACK-SAMPLES\ -s sigma/ --mapping mappings/sigma-event-logs-all.yml -r rules/

@Marwolf - Thanks for pointing this out. This should be fixed now.