Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

importing pcap to Sysmon viewer #17

Open
iD4rksid3 opened this issue Feb 10, 2020 · 1 comment
Open

importing pcap to Sysmon viewer #17

iD4rksid3 opened this issue Feb 10, 2020 · 1 comment

Comments

@iD4rksid3
Copy link

I run sysmonBox and then opened sysmon viewer > imported pcap but I can't find any additional data e.g the pcap related to a dns query, or am I missing something, how does it work?

@nshalabi
Copy link
Owner

Thank you for your feedback.

I am currently reviewing it, SysmonBox definitely needs more testing and enhancements, there are threading issues reported too when attempting to dump the Sysmon events logs, so a correlation might not happen between captured packets and Sysmon events logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants