Skip to content
This repository has been archived by the owner on Aug 5, 2024. It is now read-only.

Release 0.8v produces improper messages #21

Open
GilPasi opened this issue Jul 24, 2024 · 0 comments
Open

Release 0.8v produces improper messages #21

GilPasi opened this issue Jul 24, 2024 · 0 comments

Comments

@GilPasi
Copy link

GilPasi commented Jul 24, 2024

Specifically the compiled package v0.8 produces event messages in the format "event":{{}} instead of a valid json format: {}. However this problem does not occur in the source version (when built manually). I suggest to re-upload the compiled one.

Example of the invalid message:
"event":{{"ProviderGuid":"7dd42a49-5329-4832-8dfd-43d979153a88","YaraMatch":[],"ProviderName":"Gil100-Windows-Kernel-Network","EventName":"KERNEL_NETWORK_TASK_TCPIP/Datareceived.","Opcode":11,"OpcodeName":"Datareceived.","TimeStamp":"2024-07-22T14:29:27.6882177+03:00","ThreadID":10008,"ProcessID":1224,"ProcessName":"svchost","PointerSize":8,"EventDataLength":28,"XmlEventData":{"FormattedMessage":"TCPv4: 43 bytes received from 1,721,149,632:15,629 to -23,680,832:14,326. ","connid":"0","sport":"15,629","_PID":"820","seqnum":"0","MSec":"339.9806","saddr":"1,721,149,632","size":"43","PID":"1224","dport":"14,326","TID":"10008","ProviderName":"Microsoft-Windows-Kernel-Network","PName":"","EventName":"KERNEL_NETWORK_TASK_TCPIP/Datareceived.","daddr":"-23,680,832"}}}

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant