Skip to content

Missing even data in Details #1081

Answered by YamatoSecurity
zpravaiz asked this question in Q&A
Discussion options

You must be logged in to vote

@zpravaiz Hayabusa has rules to detect all sysmon events. (If it doesn't detect a sysmon event that you need then that would be considered a bug so please report it but you should be able to detect all sysmon events.) By default, only the most important fields in an event are outputted in the Details column. You can easy get all field information by changing the output profile as @hitenkoku mentioned to any of the following:

- all-field-info
- all-field-info-verbose
- super-verbose
- timesketch-verbose

Just add -p super-verbose to the command line to get as much info as possible.
This is all explained in the readme but many people ask about this so in the next version coming out in a few…

Replies: 4 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@AndrewRathbun
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by YamatoSecurity
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants