Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

wineventlog: add support for replaying evtx files #3278

Merged
merged 12 commits into from
Oct 16, 2024
Merged

Conversation

blotus
Copy link
Member

@blotus blotus commented Oct 4, 2024

  • Add support for replaying Windows evtx files
  • Improve XML parsing helpers performance by caching the parsed document instead of rebuilding it each time we want to extract something.

Copy link

github-actions bot commented Oct 4, 2024

@blotus: There are no 'kind' label on this PR. You need a 'kind' label to generate the release automatically.

  • /kind feature
  • /kind enhancement
  • /kind refactoring
  • /kind fix
  • /kind chore
  • /kind dependencies
Details

I am a bot created to help the crowdsecurity developers manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the BirthdayResearch/oss-governance-bot repository.

Copy link

github-actions bot commented Oct 4, 2024

@blotus: There are no area labels on this PR. You can add as many areas as you see fit.

  • /area agent
  • /area local-api
  • /area cscli
  • /area appsec
  • /area security
  • /area configuration
Details

I am a bot created to help the crowdsecurity developers manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the BirthdayResearch/oss-governance-bot repository.

@blotus
Copy link
Member Author

blotus commented Oct 4, 2024

/kind feature
/area agent

Copy link

codecov bot commented Oct 4, 2024

Codecov Report

Attention: Patch coverage is 67.24138% with 57 lines in your changes missing coverage. Please review.

Project coverage is 39.28%. Comparing base (9976616) to head (2aa1b67).
Report is 2 commits behind head on master.

Files with missing lines Patch % Lines
...isition/modules/wineventlog/wineventlog_windows.go 58.19% 40 Missing and 11 partials ⚠️
pkg/exprhelpers/xml.go 88.23% 4 Missing and 2 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #3278      +/-   ##
==========================================
+ Coverage   39.21%   39.28%   +0.06%     
==========================================
  Files         480      480              
  Lines       62075    62217     +142     
==========================================
+ Hits        24341    24440      +99     
- Misses      35091    35124      +33     
- Partials     2643     2653      +10     
Flag Coverage Δ
bats 31.45% <14.28%> (+0.07%) ⬆️
unit-linux 34.77% <90.47%> (+0.04%) ⬆️
unit-windows 24.74% <67.24%> (+0.08%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

pkg/exprhelpers/xml.go Outdated Show resolved Hide resolved
@blotus blotus merged commit d8bc17b into master Oct 16, 2024
17 checks passed
@blotus blotus deleted the windows-evtx-replay branch October 16, 2024 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants