-
Notifications
You must be signed in to change notification settings - Fork 383
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
stop() module functions not executed/reached? #2120
Comments
probably due to subprocess in frond of stop, idk, i dont use those modules so i can't confirm why they doest work |
Could it be that debug messages are not showing due to the lack of |
@kevoreilly No, because I see the "debug" messages generated by start(). Here is an example:
Could this be the reason?
|
There's a lot of analyzer changes that just merged yesterday as part of #2041. It's worth trying this again as the analyzer has changed quite a bit, in an effort to improve scenarios like these. |
Prerequisites
Please answer the following questions for yourself before submitting an issue.
Expected Behavior
Some modules are enabled but no data is collected at the end of the analysis. the stop() function seems to not be executed.
Current Behavior
This has been seen with the following 3 modules: sysmon, evtx, procmon. They are initialized, I see some debugging info when the analysis is launched but no data is returned at the end of the analysis...
Steps to Reproduce
Analyse a file... Analysis is completed:
However data is not collected (directories are empty in the analysis subdir and no logs are generated. For example, for evtx, it should log something like (according to the source code):
The text was updated successfully, but these errors were encountered: