fix: Fixed key to ParentPGUID
. Apply PID
hex conversion process only if PID
is not decimal
#50
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Changed
PID
andParentPGUID
are not output intimeline-suspicious-process
csv output #49ParentGUID
toParentPGUID
PID
hex conversion process only ifPID
is not decimalHexToDecimal
field data mapping hayabusa#1154Test
Environment
Test1(default jsonl)
Event ID 4688 Security
PID
1216
and1404
are output.4688 does not have ParentPGUID, so it is not output.
Event ID 1 Sysmon
PID
1524
and8636
and60
are output.ParentPGUID
A57649D1-124E-61F1-503D-8E1500000000
and3E153517-43C6-630C-F202-000000000400
and3E153517-4EE4-630C-BA00-000000000500
are output.Test2(-F, --no-field-data-mapping jsonl)
Event ID 4688 Security
PID
1216
and1404
are output.4688 does not have ParentPGUID, so it is not output.
Event ID 1 Sysmon
PID
1524
and8636
and60
are output.ParentPGUID
A57649D1-124E-61F1-503D-8E1500000000
and3E153517-43C6-630C-F202-000000000400
and3E153517-4EE4-630C-BA00-000000000500
are output.I would appreciate it if you could review when you have time🙏