Salin guna rawcopy
RawCopy.exe /FileNamePath:C:0 /OutputPath:C:\Audit /OutputName:MFT_C.bin
Salin guna rawcopy
RawCopy.exe /FileNamePath:C:0 /OutputPath:C:\Audit /OutputName:MFT_C.bin
This not work as expected because * is interprate as literal *:
http.request.referrer: "https://example.com*"
Instead use this:
http.request.referrer: https\://example.com*
File path issue in windows:
Kibana display value as:
C:\WINDOWS\system32\MRT.exe
But if you check in json, actual value stored in elastic is:
"c:\\windows\\system32\\mrt.exe"
Thus, to find all files in folder system32(and sub folder) you need to escape the backslash character:
file.path.caseless : c\:\\\\windows\\\\system32\\\\*
To find all files in folder system32(exclude sub folder):
file.path.caseless : c\:\\\\windows\\\\system32\\\\* and not file.path.caseless : c\:\\\\windows\\\\system32\\\\*\\\\*
java.lang.IllegalStateException: Unable to access 'path.repo' (/mnt/remote_snapshot_on_st02/snap_dir) at org.elasticsearch.bootstrap.FilePermissionUtils.addDirectoryPath(FilePermissionUtils.java:66) ~[elasticsearch-8.8.1.jar:?]This happen because elasticsearh process is own by user elasticsearch. You need to mount the dir using elasticsearch acc. sudo su -u elasticsearch sshfs myacc@10.10.10.10:/data/my_elastic_snapshot_dir/ /mnt/my_snapshot_dir Of course you need to have set path.repo on your elasticsearch.yml path.repo: [/mnt/my_snapshot_dir/the_snapshot_dir_on_remote]
1)
2)
ref: https://www.cellstream.com/reference-reading/tipsandtricks/431-finding-text-strings-in-wireshark-captures
history of ip has been assign to your pc
Ada 2 command yg boleh senaraikan IP yg pc anda dapat dari DHCP.
1) sudo cat /var/log/syslog | grep -Ei 'dhcp' | grep ip_address
2) sudo journalctl | grep -Ei 'dhcp' | grep ip_address
$ apt-cache madison calc calc | 2.12.7.2-4 | http://10.108.201.140/ubuntu/mirror/archive.ubuntu.com/ubuntu focal/universe amd64 Packages calc | 2.10.18-dfsg-2build1 | http://archive.ubuntu.com/ubuntu xenial/multiverse amd64 Packages
500 http://cm.archive.ubuntu.com/ubuntu xenial/multiverse amd64 Packages
ref:
https://linuxopsys.com/topics/install-specific-version-package-apt