-
Notifications
You must be signed in to change notification settings - Fork 160
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
add ability to parse OriginalFilename #350
Comments
Seems reasonable to me, would you like to make a PR adding this? (ideally backwards compatible/non breaking) :) |
I can try at some point but its beyond my capabilities unfortunately. When I get some more time, I'll keep digging into it. Thanks |
FYI I'm working on this feature as a part of resource parser. The work is almost done and PR should be submitted in a few days I guess.
|
This was referenced Oct 31, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
MS doc: https://learn.microsoft.com/en-us/windows/win32/menurc/string-str?redirectedfrom=MSDN
Yara rule support for field: https://yara.readthedocs.io/en/v3.2.0/modules/pe.html
This is a useful field in threat hunting and forensics in general.
thanks
The text was updated successfully, but these errors were encountered: