diff --git a/Requirements.txt b/Requirements.txt index ce7158b..e4ffa7a 100644 --- a/Requirements.txt +++ b/Requirements.txt @@ -1,2 +1,8 @@ -netaddr evtx +netaddr +numpy +pandas +python-dateutil +pytz +six +XlsxWriter diff --git a/lib/EvtxDetection.py b/lib/EvtxDetection.py index 9bc4d9a..e0722a8 100644 --- a/lib/EvtxDetection.py +++ b/lib/EvtxDetection.py @@ -1084,7 +1084,7 @@ def detect_events_security_log(file_name): for user in PasswordSpray: if len(PasswordSpray[user])>3: Event_desc = "Password Spray Detected by user ( "+user+" )" - Security_events[0]['Date and Time'].append(datetime.now()) + Security_events[0]['Date and Time'].append(record["timestamp"]) Security_events[0]['Detection Rule'].append("Password Spray Detected") Security_events[0]['Detection Domain'].append("Threat") Security_events[0]['Severity'].append("High")