plaso_filters
plaso_filters copied to clipboard
Add periods to user registry section wildcards
Hi,
Thanks for sharing these plaso filters! I noticed that when I was using the filter_windows.txt list with log2timeline, user registry hives weren't being pulled in. I'm pretty new to this toolset but I assumed it's because it's parsing the filters as regexes... adding periods before each of the *s seemed to fix the issue for me, but perhaps I was just doing something else wrong.
cheers,Ben