","body@stripHtml({\"removeProcessingText\":true,\"removeSpoilerMarkup\":true,\"removeTocMarkup\":true,\"truncateLength\":200})@stringLength":"203","postTime":"2024-11-07T07:50:54.945-08:00","lastPublishTime":"2024-11-07T07:50:54.945-08:00","images":{"__typename":"AssociatedImageConnection","edges":[{"__typename":"AssociatedImageEdge","cursor":"MjUuM3wyLjF8b3wyNXxfTlZffDE","node":{"__ref":"AssociatedImage:{\"url\":\"https://community.immersivelabs.com/t5/s/dnvaw96485/images/bS05NjItOG93aEEz?revision=1\"}"}}],"totalCount":1,"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"attachments":{"__typename":"AttachmentConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"solution":true,"metrics":{"__typename":"MessageMetrics","views":266},"placeholder":false,"originalMessageForPlaceholder":null,"videos":{"__typename":"VideoConnection","edges":[],"totalCount":0,"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"isEscalated":null,"entityType":"FORUM_REPLY","eventPath":"category:help/community:dnvaw96485board:help/message:911/message:962","customFields":[],"readOnly":false,"repliesCount":2,"body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"203","kudosSumWeight":1,"visibilityScope":"PUBLIC","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[{"__typename":"MessageEdge","cursor":"MjUuM3wyLjF8b3wzfDE0OjAsMzk6MXwx","node":{"__ref":"ForumReplyMessage:message:965"}}]}},"ModerationData:moderation_data:960":{"__typename":"ModerationData","id":"moderation_data:960","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":"member"},"ModerationData:moderation_data:948":{"__typename":"ModerationData","id":"moderation_data:948","status":"APPROVED","rejectReason":null},"User:user:491":{"__typename":"User","id":"user:491","login":"autom8on","uid":491,"deleted":false,"avatar":{"__typename":"UserAvatar","url":"https://community.immersivelabs.com/t5/s/dnvaw96485/images/dS00OTEtOTVxRUZ2?image-coordinates=0%2C0%2C400%2C400"},"rank":{"__ref":"Rank:rank:10"},"email":"","messagesCount":29,"biography":null,"topicsCount":2,"kudosReceivedCount":43,"kudosGivenCount":16,"kudosWeight":1,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2024-10-31T05:28:15.431-07:00","confirmEmailStatus":null},"followersCount":null,"solutionsCount":2,"entityType":"USER","eventPath":"community:dnvaw96485/user:491"},"ForumReplyMessage:message:948":{"__typename":"ForumReplyMessage","id":"message:948","revisionNum":1,"uid":948,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Forum:board:help"},"conversation":{"__ref":"Conversation:conversation:911"},"subject":"Re: FIN7 Threat Hunting with Splunk: Ep.3 – Execution Logs","readOnly":false,"editFrozen":false,"moderationData":{"__ref":"ModerationData:moderation_data:948"},"body":"
I suspect the lab hasn't changed a great deal since I last did it in 2021. Sadly, my notes aren't amazing for the final question - but I've just checked, and the answer I've got in my notes is still correct (\"d12... ...dbc\"). The sum total of my notes for that question were \"Search for stager.ps1 AND scriptblock to find the bits. Then cut and paste them into a single file.\"
I'll try and find time to go back and recreate it again, and see if I get the same answer...
Random thought - there couldn't be some weird DOS/Unix formatting weirdness going on if you're mixing OSes, could there?
","body@stringLength":"639","rawBody":"I suspect the lab hasn't changed a great deal since I last did it in 2021. Sadly, my notes aren't amazing for the final question - but I've just checked, and the answer I've got in my notes is still correct (\"d12... ...dbc\"). The sum total of my notes for that question were \"Search for stager.ps1 AND scriptblock to find the bits. Then cut and paste them into a single file.\"
I'll try and find time to go back and recreate it again, and see if I get the same answer...
Random thought - there couldn't be some weird DOS/Unix formatting weirdness going on if you're mixing OSes, could there?
","author":{"__ref":"User:user:491"},"isEscalated":null,"postTime":"2024-11-07T05:39:39.870-08:00","solution":false,"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"repliesCount":14},"Revision:revision:960_1":{"__typename":"Revision","id":"revision:960_1","lastEditTime":"2024-11-07T07:44:05.248-08:00"},"QueryVariables:ReplyList:message:960:1":{"__typename":"QueryVariables","id":"ReplyList:message:960:1","value":{"id":"message:960","first":10,"sorts":{"kudosSumWeight":{"direction":"DESC","order":0},"postTime":{"direction":"ASC","order":1}},"repliesFirst":3,"repliesFirstDepthThree":1,"repliesSorts":{"kudosSumWeight":{"direction":"DESC","order":0},"postTime":{"direction":"ASC","order":1}},"useAvatar":true,"useAuthorLogin":true,"useAuthorRank":true,"useBody":true,"useKudosCount":true,"useTimeToRead":false,"useMedia":false,"useReadOnlyIcon":false,"useRepliesCount":true,"useSearchSnippet":false,"useAcceptedSolutionButton":true,"useSolvedBadge":false,"useAttachments":false,"attachmentsFirst":5,"useTags":false,"useNodeAncestors":false,"useUserHoverCard":false,"useNodeHoverCard":false,"useModerationStatus":true,"usePreviewSubjectModal":false,"useMessageStatus":true}},"CachedAsset:text:en_US-components/community/NavbarDropdownToggle-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-components/community/NavbarDropdownToggle-1746542127000","value":{"ariaLabelClosed":"Press the down arrow to open the menu"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/users/UserAvatar-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/users/UserAvatar-1746542127000","value":{"altText":"{login}'s avatar","altTextGeneric":"User's avatar"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/ranks/UserRankLabel-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/ranks/UserRankLabel-1746542127000","value":{"altTitle":"Icon for {rankName} rank"},"localOverride":false},"CachedAsset:text:en_US-components/tags/TagView/TagViewChip-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-components/tags/TagView/TagViewChip-1746542127000","value":{"tagLabelName":"Tag name {tagName}"},"localOverride":false},"CachedAsset:text:en_US-components/messages/AcceptedSolutionButton-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-components/messages/AcceptedSolutionButton-1746542127000","value":{"accept":"Mark as Solution","accepted":"Marked as Solution","errorHeader":"Error!","errorAdd":"There was an error marking as solution.","errorRemove":"There was an error unmarking as solution.","solved":"Solved","topicAlreadySolvedErrorTitle":"Solution Already Exists","topicAlreadySolvedErrorDesc":"Refresh the browser to view the existing solution"},"localOverride":false},"CachedAsset:text:en_US-components/messages/ThreadedReplyList-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-components/messages/ThreadedReplyList-1746542127000","value":{"title":"{count, plural, one{# Reply} other{# Replies}}","title@board:BLOG":"{count, plural, one{# Comment} other{# Comments}}","title@board:TKB":"{count, plural, one{# Comment} other{# Comments}}","title@board:IDEA":"{count, plural, one{# Comment} other{# Comments}}","title@board:OCCASION":"{count, plural, one{# Comment} other{# Comments}}","noRepliesTitle":"No Replies","noRepliesTitle@board:BLOG":"No Comments","noRepliesTitle@board:TKB":"No Comments","noRepliesTitle@board:IDEA":"No Comments","noRepliesTitle@board:OCCASION":"No Comments","noRepliesDescription":"Be the first to reply","noRepliesDescription@board:BLOG":"Be the first to comment","noRepliesDescription@board:TKB":"Be the first to comment","noRepliesDescription@board:IDEA":"Be the first to comment","noRepliesDescription@board:OCCASION":"Be the first to comment","messageReadOnlyAlert:BLOG":"Comments have been turned off for this post","messageReadOnlyAlert:TKB":"Comments have been turned off for this article","messageReadOnlyAlert:IDEA":"Comments have been turned off for this idea","messageReadOnlyAlert:FORUM":"Replies have been turned off for this discussion","messageReadOnlyAlert:OCCASION":"Comments have been turned off for this event"},"localOverride":false},"CachedAsset:text:en_US-components/nodes/NodeView/NodeViewCard-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-components/nodes/NodeView/NodeViewCard-1746542127000","value":{"title":"{nodeTitle} ","creationDate":"Created: {creationDate}","ownedBy":"Owned by: {owners}{text}","showOwnerListText":", and {ownersCount} more","unreadCount":"{count} unread","nodeViewDrawerBtn":"Node view drawer for {place}","drawerActionTooltip":"Show category children"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageView/MessageViewInline-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageView/MessageViewInline-1746542127000","value":{"bylineAuthor":"{bylineAuthor}","bylineBoard":"{bylineBoard}","anonymous":"Anonymous","place":"Place {bylineBoard}","gotoParent":"Go to parent {name}"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/common/Pager/PagerLoadMore-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/common/Pager/PagerLoadMore-1746542127000","value":{"loadMore":"Show More"},"localOverride":false},"ModerationData:moderation_data:961":{"__typename":"ModerationData","id":"moderation_data:961","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":"member"},"ForumReplyMessage:message:961":{"__typename":"ForumReplyMessage","author":{"__ref":"User:user:491"},"id":"message:961","revisionNum":1,"uid":961,"depth":3,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Forum:board:help"},"parent":{"__ref":"ForumReplyMessage:message:960"},"conversation":{"__ref":"Conversation:conversation:911"},"subject":"Re: FIN7 Threat Hunting with Splunk: Ep.3 – Execution Logs","moderationData":{"__ref":"ModerationData:moderation_data:961"},"body":"Yeah - there seem to be some slightly weird timings going on with the frequency with which responses have been appearing on this page. Since I first looked, responses are now visible which seem to predate when I was looking here initially (so I'm not sure why I didn't see them before?).
You can't be far away from the right answer - good luck! :-)
","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"203","kudosSumWeight":2,"repliesCount":0,"postTime":"2024-11-07T07:49:00.762-08:00","lastPublishTime":"2024-11-07T07:49:00.762-08:00","metrics":{"__typename":"MessageMetrics","views":125},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"isEscalated":null,"solution":false,"entityType":"FORUM_REPLY","eventPath":"category:help/community:dnvaw96485board:help/message:911/message:961","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"ModerationData:moderation_data:965":{"__typename":"ModerationData","id":"moderation_data:965","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":"member"},"ForumReplyMessage:message:965":{"__typename":"ForumReplyMessage","uid":965,"id":"message:965","revisionNum":1,"author":{"__ref":"User:user:512"},"readOnly":false,"repliesCount":1,"depth":4,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Forum:board:help"},"parent":{"__ref":"AcceptedSolutionMessage:message:962"},"conversation":{"__ref":"Conversation:conversation:911"},"subject":"Re: FIN7 Threat Hunting with Splunk: Ep.3 – Execution Logs","moderationData":{"__ref":"ModerationData:moderation_data:965"},"body":"OH ..... MY ....... GAHHHHHHH! lol .... she worked for me. Hats off to you and autom8on!!
","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"103","kudosSumWeight":3,"postTime":"2024-11-07T08:59:13.964-08:00","lastPublishTime":"2024-11-07T08:59:13.964-08:00","metrics":{"__typename":"MessageMetrics","views":27},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"isEscalated":null,"solution":false,"entityType":"FORUM_REPLY","eventPath":"category:help/community:dnvaw96485board:help/message:911/message:965","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[{"__typename":"MessageEdge","cursor":"MjUuM3wyLjF8b3wxfDE0OjAsMzk6MXwx","node":{"__ref":"ForumReplyMessage:message:974"}}]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"ModerationData:moderation_data:974":{"__typename":"ModerationData","id":"moderation_data:974","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":"member"},"ForumReplyMessage:message:974":{"__typename":"ForumReplyMessage","author":{"__ref":"User:user:517"},"id":"message:974","revisionNum":1,"uid":974,"depth":5,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Forum:board:help"},"parent":{"__ref":"ForumReplyMessage:message:965"},"conversation":{"__ref":"Conversation:conversation:911"},"subject":"Re: FIN7 Threat Hunting with Splunk: Ep.3 – Execution Logs","moderationData":{"__ref":"ModerationData:moderation_data:974"},"body":"Glad it worked, it had been annoying me for a couple of days too!
","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"67","kudosSumWeight":1,"repliesCount":0,"postTime":"2024-11-08T00:46:32.979-08:00","lastPublishTime":"2024-11-08T00:46:32.979-08:00","metrics":{"__typename":"MessageMetrics","views":22},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"isEscalated":null,"solution":false,"entityType":"FORUM_REPLY","eventPath":"category:help/community:dnvaw96485board:help/message:911/message:974","customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"CachedAsset:text:en_US-shared/client/components/nodes/NodeTitle-1746542127000":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/nodes/NodeTitle-1746542127000","value":{"nodeTitle":"{nodeTitle, select, community {Community} other {{nodeTitle}}} "},"localOverride":false}}}},"page":"/forums/ForumMessagePage/ForumMessagePage","query":{"boardId":"help","messageSubject":"fin7-threat-hunting-with-splunk-ep-3-–-execution-logs","messageId":"911","replyId":"960"},"buildId":"ISAhs0UxT148eG089lpQq","runtimeConfig":{"buildInformationVisible":false,"logLevelApp":"info","logLevelMetrics":"info","openTelemetryClientEnabled":false,"openTelemetryConfigName":"immersivelabs","openTelemetryServiceVersion":"25.3.0","openTelemetryUniverse":"prod","openTelemetryCollector":"http://localhost:4318","openTelemetryRouteChangeAllowedTime":"5000","apolloDevToolsEnabled":false,"inboxMuteWipFeatureEnabled":false},"isFallback":false,"isExperimentalCompile":false,"dynamicIds":["./components/seo/QAPageSchema/QAPageSchema.tsx","./components/community/Navbar/NavbarWidget.tsx","./components/community/Breadcrumb/BreadcrumbWidget.tsx","./components/messages/TopicWithThreadedReplyListWidget/TopicWithThreadedReplyListWidget.tsx","./components/messages/MessageView/MessageViewStandard/MessageViewStandard.tsx","./components/featured/places/FeaturedPlacesWidget/FeaturedPlacesWidget.tsx","./components/messages/RelatedContentWidget/RelatedContentWidget.tsx","./components/messages/MessageListForNodeByRecentActivityWidget/MessageListForNodeByRecentActivityWidget.tsx","./components/community/FooterWidget/FooterWidget.tsx","./components/customComponent/CustomComponent/CustomComponent.tsx","./components/featured/places/AddFeaturedPlacesModal/AddFeaturedPlacesModal.tsx","./components/community/FooterWidgetHelpLink/FooterWidgetHelpLink.tsx","./components/community/KhorosLogo/KhorosLogo.tsx","../shared/client/components/common/List/UnwrappedList/UnwrappedList.tsx","./components/tags/TagView/TagView.tsx","./components/tags/TagView/TagViewChip/TagViewChip.tsx","../shared/client/components/common/List/UnstyledList/UnstyledList.tsx","./components/messages/MessageView/MessageView.tsx","../shared/client/components/common/List/GridList/GridList.tsx","./components/nodes/NodeView/NodeView.tsx","./components/nodes/NodeView/NodeViewCard/NodeViewCard.tsx","./components/messages/MessageView/MessageViewInline/MessageViewInline.tsx","../shared/client/components/common/Pager/PagerLoadMore/PagerLoadMore.tsx","../shared/client/components/common/List/ListGroup/ListGroup.tsx","./components/customComponent/CustomComponentContent/TemplateContent.tsx"],"appGip":true,"scriptLoader":[]}