Regular Expressions 101

Community Patterns

ADAXES Samples

0

Regular Expression
PCRE (PHP <7.3)

/
<USER:(?<severity>[^>]*).*?ADAXES\s(?:(?<vmid>[^\|@]*)|[^(]+\((?<login>[^@]*)\@(?<domainorigin>[^)]*)\))\|(?<vendorinfo>(?:Add|Remove|Run|Create|Sign in|Change|Modify|Execute|Create|Deliver|Send)\s+(?:(?:\'(?<account>[^(]*)\s(?<group>[^']*)'.*?(?:from|to)\s+'(?<object>[^']*)'|PowerShell\s+script(?:[^']*\'(?<command>[^']*)'\s+for\s+'(?<object>[^']*).*?)|(?:\'(?<account>[^(]*)\s(?<group>[^']*)'.*)|(?:to\sWeb\s+Interface.*?'(?<session>[^']*)'\s+from\s'(?<sip>\d+\.\d+\.\d+\.\d+)')|password\sfor\s\'(?<account>[^(]*)\s(?<group>[^']*).*|HTML.*?(?:to|for)\s+'?(?<account>[^@'\(]*)(?:@|\s)[^\|]*|scheduled\stask\s'(?<subject>[^']*)\'\s+for\s+\'(?<account>[^(]*)\s(?<group>[^']*).*)|e-mail\snotification\s\((?<subject>.*?)'\)))\|(?<result>.*)$
/
gmJ

Description

no description available

Submitted by anonymous - 3 years ago