Tools Supported | autoruns, kape, kansa, plaso, mactime, macrobber, volatility, sabonis |
---|---|
Advanced Artifact Support (HAM) | svclist, pslist, flist, amcache, evtx, winreg, fstl |
Function | Usage | Type | Description |
---|---|---|---|
build_lm_dataset() | build_lm_dataset(options) | CLI | Build a lateral movement dataset from a log event dataset. |
find_lm_anomalies() | find_lm_anomalies(options) | CLI | Identify anomalous lateral movements (LM) in a LM dataset. |
You can find examples on how to use CORE functions here.