Hi
I would like to know if i can user the last seen metric of a user in a YARA rule , if yes while i am using i am not seeing the result
My YARA rule is this
Hi
I would like to know if i can user the last seen metric of a user in a YARA rule , if yes while i am using i am not seeing the result
My YARA rule is this
Yes it can as John Stoner shows here in his New to Chronicle Blog. I'm not certain but maybe it's last_seen_time.seconds instead of last_seen.seconds? I am pretty certain it's just a small syntax error though or maybe a missing line?
the last_seen_time is not available for the USER entity type...
Based on the doc:
"The first_seen_time and last_seen_time fields are populated with entities that describe a domain, IP address, and file (hash). For entities that describe a user or asset, only the first_seen_time field is populated. These values are not calculated for entities that describe other types, such as a group or resource."
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.