From 640244d9d9ef4bef85520bc306c93c139d09e546 Mon Sep 17 00:00:00 2001 From: Phill Moore Date: Tue, 31 Dec 2024 15:49:29 +1100 Subject: [PATCH 1/2] Update hayabusa_OfflineEventLogs.mkape add json output --- Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape b/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape index d98ea53ca..e0425eb71 100644 --- a/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape +++ b/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape @@ -10,6 +10,10 @@ Processors: Executable: hayabusa\hayabusa.exe CommandLine: csv-timeline -d %sourceDirectory% --profile standard -w --quiet --UTC -o %destinationDirectory%\hayabusa_events_offline.csv ExportFormat: csv + - + Executable: hayabusa\hayabusa.exe + CommandLine: json-timeline -d %sourceDirectory% --profile standard -w --quiet --UTC -o %destinationDirectory%\hayabusa_events_offline.jsonl -L + ExportFormat: json # Documentation # Create a folder "hayabusa" within the "Modules\bin" KAPE folder From 8e1ab91591f725737383833348bf0ac37a04053a Mon Sep 17 00:00:00 2001 From: Phill Moore Date: Tue, 31 Dec 2024 15:49:50 +1100 Subject: [PATCH 2/2] Update hayabusa_OfflineEventLogs.mkape update version number --- Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape b/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape index e0425eb71..81178b2c7 100644 --- a/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape +++ b/Modules/Apps/GitHub/Hayabusa/hayabusa_OfflineEventLogs.mkape @@ -1,7 +1,7 @@ Description: Hayabusa a timeline generator for Windows event logs - Offline Category: EventLogs Author: Georg Lauenstein (sure[secure]) -Version: 1.4 +Version: 1.5 Id: 49f9cd2d-3da5-4349-a9aa-c2b450582ccc BinaryUrl: https://github.com/Yamato-Security/hayabusa/releases ExportFormat: csv