CARVIEW |
Select Language
HTTP/2 200
date: Tue, 29 Jul 2025 02:41:51 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
x-repository-download: git clone https://github.com/rabbitstack/fibratus.git
etag: W/"31ee502c87229020856de1fb692fbd59"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=B0Kz0BhFlwT1opm3nELd5%2FqhDY7Aq%2FQj4b5GrWaRw5NlW85g2UEu6ZUTpFD4qrINXLOh04gp%2BGMlcrwmgZo6IV5QZrgcgKBk5vBZqWIa2FLV6Tw6fQr2ruGw85BfluoRIpWj6lUR4kTOdzvx9r6ly0kDv3aLwR2c3wqdeFOVNIEI0G1lh98DfSxOxKV%2BKekOHuoVXlm87FQeDfu8l3K4i66Yz7cVix0cq0bGpSnEG%2Fqn3T0jqUBtMMRNMpHOjTyVPAOax9eA%2BJvarpANHiIJ7g%3D%3D--Ze4Sk9PnPVUAwLf3--bo4C%2F7SiNYk3lywJndzGoQ%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.2072255503.1753756911; Path=/; Domain=github.com; Expires=Wed, 29 Jul 2026 02:41:51 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Wed, 29 Jul 2026 02:41:51 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: 88AE:E64EF:1E11DE:2C97FB:688834EF
refactor(filter,rules): Deprecate pe.ps.child.file.name field · rabbitstack/fibratus@b4fb489 · GitHub
Copy file name to clipboardExpand all lines: pkg/filter/accessor_windows.go
Copy file name to clipboardExpand all lines: pkg/filter/fields/fields_windows.go
Copy file name to clipboardExpand all lines: rules/defense_evasion_regsvr32_scriptlet_execution.yml
Copy file name to clipboardExpand all lines: rules/defense_evasion_system_binary_proxy_execution_via_rundll32.yml
Skip to content
Navigation Menu
{{ message }}
-
-
Notifications
You must be signed in to change notification settings - Fork 202
Commit b4fb489
committed
refactor(filter,rules): Deprecate pe.ps.child.file.name field
Introduce a new filter field ps.child.pe.file.name that is uniform with other ps.child.* field.1 parent f5c330f commit b4fb489Copy full SHA for b4fb489
File tree
Expand file treeCollapse file tree
4 files changed
+11
-8
lines changedFilter options
- pkg/filter
- fields
- rules
Expand file treeCollapse file tree
4 files changed
+11
-8
lines changedpkg/filter/accessor_windows.go
Copy file name to clipboardExpand all lines: pkg/filter/accessor_windows.go+3-3Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1047 | 1047 |
| |
1048 | 1048 |
| |
1049 | 1049 |
| |
1050 |
| - | |
| 1050 | + | |
1051 | 1051 |
| |
1052 | 1052 |
| |
1053 |
| - | |
| 1053 | + | |
1054 | 1054 |
| |
1055 | 1055 |
| |
1056 | 1056 |
| |
| |||
1166 | 1166 |
| |
1167 | 1167 |
| |
1168 | 1168 |
| |
1169 |
| - | |
| 1169 | + | |
1170 | 1170 |
| |
1171 | 1171 |
| |
1172 | 1172 |
| |
|
pkg/filter/fields/fields_windows.go
Copy file name to clipboardExpand all lines: pkg/filter/fields/fields_windows.go+6-3Lines changed: 6 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
152 | 152 |
| |
153 | 153 |
| |
154 | 154 |
| |
| 155 | + | |
| 156 | + | |
155 | 157 |
| |
156 | 158 |
| |
157 | 159 |
| |
| |||
471 | 473 |
| |
472 | 474 |
| |
473 | 475 |
| |
474 |
| - | |
| 476 | + | |
475 | 477 |
| |
476 | 478 |
| |
477 | 479 |
| |
| |||
482 | 484 |
| |
483 | 485 |
| |
484 | 486 |
| |
485 |
| - | |
| 487 | + | |
486 | 488 |
| |
487 | 489 |
| |
488 | 490 |
| |
| |||
658 | 660 |
| |
659 | 661 |
| |
660 | 662 |
| |
| 663 | + | |
661 | 664 |
| |
662 | 665 |
| |
663 | 666 |
| |
| |||
774 | 777 |
| |
775 | 778 |
| |
776 | 779 |
| |
777 |
| - | |
| 780 | + | |
778 | 781 |
| |
779 | 782 |
| |
780 | 783 |
| |
|
rules/defense_evasion_regsvr32_scriptlet_execution.yml
Copy file name to clipboardExpand all lines: rules/defense_evasion_regsvr32_scriptlet_execution.yml+1-1Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
18 | 18 |
| |
19 | 19 |
| |
20 | 20 |
| |
21 |
| - | |
| 21 | + | |
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
|
rules/defense_evasion_system_binary_proxy_execution_via_rundll32.yml
Copy file name to clipboardExpand all lines: rules/defense_evasion_system_binary_proxy_execution_via_rundll32.yml+1-1Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
| 29 | + | |
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
|
You can’t perform that action at this time.
0 commit comments