Releases: opencybersecurityalliance/kestrel-lang
Releases · opencybersecurityalliance/kestrel-lang
v1.0.8
v1.0.7
Summer Day
Multiple fixes and improvements.
Process entity recognition is large improved in this release. Now it uses pid
or name
as pre-filter in prefetch, and then use first_observed
and last_observed
time to filter prefetched processes with comprehensive logic. The logic works on both Windows and Linux data sources.
Periodic Fixes And Improvements
- Fix FIND with network-traffic error
- Add debug flag to env variable
- Add hunting GIF to README
Multiple Improvements
- GitHub actions on unit testing and code checks
- More comprehensive entity identification logic
- Documentation typo fixes
Critical Bug Updates
-
Fixed
- Fix the timestamp parsing issue #6
- Fix version: pypi/support#214
-
Added
First Release
Open sourcing Kestrel Threat Hunting Language.
This is an alpha version release.