Evtx files with different extension
jurelou opened this issue · comments
jurelou commented
I can see that chainsaw only supports files with evtx
extension.
https://github.com/countercept/chainsaw/blob/master/src/util.rs#L56
Would it be possible to add a command line argument to check for a different file extension ?
thanks !
Alex Kornitzer commented
As in supporting other event log formats that are not evtx? Or handling evtx files that do not have the evtx extension?
jurelou commented
I mean handling evtx files that do not have the evtx extension
Alex Kornitzer commented
Awesome, cause that is on the list for v2, extension will no longer matter. It can be easily backported to v1 too to be honest.
Alex Kornitzer commented
This is addressed in v2.0.0-alpha.0