Quentin JEROME

Results 22 comments of Quentin JEROME

Hi @Kaputt4, Thank you for your support and for giving a try to the tool. One thing you should keep in mind is that endpoint API is there to provide...

Hi @Kaputt4, Sorry for this lack of consistency between the documentation and the code. I actually plan to update the documentation when the next stable release will be published. I...

Boot time -> make some computations from GetTickCount64()

Thank you @RickyXwang for reporting that issue. Unfortunately, I'll not be able to investigate this issue before monday morning. You'll very likely get a solution on next monday. Cheers

@RickyXwang, when you stop the service some statistics about number of events scanned and alerts reported is printed in `whids.log` file. Can you please confirm both these statistics shows zeros...

@RickyXwang I just saw a something abnormal in your logs, the line with `Failed to delete autologger` ! This version of the EDR uses ETW autologger to make its job...

Hi @RickyXwang and @badboycxcc, I think I have fixed your issue ! It was due to two silly bugs introduced while refactoring some part of the code. One of them...

Hi @badboycxcc, Can you confirm please confirm if it works for you ?

This is what I would qualify as a very quick answer :+1: I'll try this out ASAP. In my opinion, it would not be choking to have this method implemented...

I tried out your patch and it seems it does not work as intended (at least in my setup). * When pasting to my terminal app, I can paste an...