| Tools Supported | autoruns, kape, kansa, plaso, mactime, macrobber, volatility, sabonis |
|---|---|
| Advanced Artifact Support (HAM) | svclist, pslist, flist, amcache, evtx, winreg, fstl |
| Function | Usage | Type | Description |
|---|---|---|---|
| build_lm_dataset() | build_lm_dataset(options) | CLI | Build a lateral movement dataset from a log event dataset. |
| find_lm_anomalies() | find_lm_anomalies(options) | CLI | Identify anomalous lateral movements (LM) in a LM dataset. |
You can find examples on how to use CORE functions here.