Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add subnet parameter to windows event logs class #10

Open
joshswimlane opened this issue Aug 6, 2020 · 1 comment
Open

Add subnet parameter to windows event logs class #10

joshswimlane opened this issue Aug 6, 2020 · 1 comment

Comments

@joshswimlane
Copy link
Contributor

From BlackHat Arsenal (Craig Bowser) asked:

When it creates logs, can you provide a subnet so that all the source IPs are in that subnet?
@joshswimlane
Copy link
Contributor Author

joshswimlane commented Aug 6, 2020

Additional comments from Craig:

Right, cause if I want to generate a lot of logs to emulate an environment then feed it into my siem, it would make sense that the source IPs (or detination IPs) are in the same network.

for that matter, when creating a bunch of logs for an environment, it would need to synch the times and use the same group of MAC addresses and usernames and machine names.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant