MCPcopy Create free account
hub / github.com/ELMERIKH/PyinMemoryPE / query

Method query

windows/winobject/event_log.py:441–470  ·  view source on GitHub ↗

Query the event with the ``ids`` or perform a query with the raw query ``filter`` Both parameters are mutually exclusive. .. note:: Here are some query examples List all events with a event data attribute named 'RuleName': ``Event/EventData/Data[@Name='

(self, filter=None, ids=None, timeout=None)

Source from the content-addressed store, hash-verified

439 self.classic_event_metadata_by_id = {} # For classic only
440
441 def query(self, filter=None, ids=None, timeout=None):
442 """Query the event with the ``ids`` or perform a query with the raw query ``filter``
443
444 Both parameters are mutually exclusive.
445
446 .. note:: Here are some query examples
447
448 List all events with a event data attribute named 'RuleName':
449 ``Event/EventData/Data[@Name='RuleName']``
450
451 List all events with a event data value of 'C:\\\\WINDOWS\\\\System32\\\\svchost.exe':
452 ``Event/EventData[Data='C:\\WINDOWS\\System32\\svchost.exe']``
453
454 List all events with an EventID of 2006:
455 ``Event/System[EventID=2006]``
456
457 List all event with a given EventID while searching for a specific field value (Sysmon for the test here)
458 ``Event/System[EventID=3] and Event/EventData/Data[@Name='DestinationIp'] and Event/EventData[Data='10.0.0.2']``
459
460 :rtype: :class:`EvtQuery`
461 """
462 if ids and filter:
463 raise ValueError("<ids> and <filter> are mutually exclusive")
464 if ids is not None:
465 if isinstance(ids, int_types):
466 ids = (ids,)
467 ids_filter = " or ".join("EventID={0}".format(id) for id in ids)
468 filter = "Event/System[{0}]".format(ids_filter)
469 query_handle = winproxy.EvtQuery(None, self.name, filter, self.DEFAULT_QUERY_FLAGS)
470 return EvtQuery(query_handle, self, timeout=timeout)
471
472 @property
473 def events(self):

Callers 1

eventsMethod · 0.95

Calls 1

EvtQueryClass · 0.70

Tested by

no test coverage detected