Hi
I'm trying to identify the registry key use for persistence, what filter do I need to apply apply?
index=*
Thanks
Tony
What data do you already have in your indexes?
Hi,
My initial filter is index=*
what filter do i need to apply to find the persistence in windows registry also filter for what port is listening for incoming connection, example port is used in a bind shell for persistence.
can you please help
thanks
Do you have an example of the type of event you are looking for?