added artifact for parsing FreeBSD utx files #903
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi,
I wrote an artifact to parse the utx file under FreeBSD.
The file is similar to the wtmp file under Linux. It records logins, logouts, boots, shutdowns and system time changes.
I appended the results from running the artifact on a test system (freebsd 14.1-RELEASE-p3 amd64)
example_results.json
Im not sure, if this artifact is better of in the Artifact Exchange or shipped by default with Velociraptor. For now, I offer it here.
If there is potential to improve the VQL, please comment so :)
Kind Regards