Hi Guys! I wanted to ask if anyone knew where the ...
# general
u
Hi Guys! I wanted to ask if anyone knew where the base FileEventSubscriber for windows is defined?
a
Hey Usama! There is no file integrity monitoring on Windows, but we (tob, or more specifically @yossarian) have implemented support for reading the NTFS journal
it's in the table named ntfs_journal_events
u
okay thank you, I was trying to make yara_events work. Im still trying to implement it, fingers crossed