Skip to content

Commit 5783382

Browse files
Update README.md
1 parent 81ab9f0 commit 5783382

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

README.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ Summary:
99

1010
You tell it the log source and/or the event ID and/or the key words and/or the number of chars in log and/or the length of the commandline, and/or the length of the log itself and the SWELF app with send just that log to your SIEM.
1111

12+
# How to get the App
13+
--------------------------------------------------------------------------------
14+
How to get the app? Click the menu option up top called 'Release' Click the newest one and then download exe.
15+
1216
# The Apps Goal
1317
--------------------------------------------------------------------------------
1418
The goal here is ideally between this app, Sysmon (or another way to monitor commandline, network connections on the endpoint, and generate hashs (sha256) for running stuff), properly configured Powershell Logging (script block logging), configured your other favorite log sources to get everything you want/need, a SIEM or Log collector (SIEM recommended)(To sort through what your do want to forward), and a little review of your log data you could in theory make a leap forward in finding the footprints that alot of security solutions just cant seem to find (fileless).

0 commit comments

Comments
 (0)