SysmonTools icon indicating copy to clipboard operation
SysmonTools copied to clipboard

importing pcap to Sysmon viewer

Open iD4rksid3 opened this issue 5 years ago • 1 comments

I run sysmonBox and then opened sysmon viewer > imported pcap but I can't find any additional data e.g the pcap related to a dns query, or am I missing something, how does it work?

iD4rksid3 avatar Feb 10 '20 19:02 iD4rksid3

Thank you for your feedback.

I am currently reviewing it, SysmonBox definitely needs more testing and enhancements, there are threading issues reported too when attempting to dump the Sysmon events logs, so a correlation might not happen between captured packets and Sysmon events logs.

nshalabi avatar Feb 19 '20 06:02 nshalabi