Normalize the intel seen filename for smb.

This commit is contained in:
Stephen Hosom 2019-02-27 09:24:52 -05:00
parent 2d3a21968e
commit 1d5eac4ee1

View file

@ -11,7 +11,9 @@ event file_new(f: fa_file)
local c = f$conns[id];
if ( c?$smb_state && c$smb_state?$current_file && c$smb_state$current_file?$name )
{
Intel::seen([$indicator=c$smb_state$current_file$name,
local split_fname = split_string(c$smb_state$current_file$name, /\\/);
local fname = split_fname[|split_fname|-1];
Intel::seen([$indicator=fname,
$indicator_type=Intel::FILE_NAME,
$f=f,
$where=SMB::IN_FILE_NAME]);