Skip to content

Initial Port to Golang#2

Open
midwestcoder2020 wants to merge 2 commits into
stuxnet999:mainfrom
midwestcoder2020:main
Open

Initial Port to Golang#2
midwestcoder2020 wants to merge 2 commits into
stuxnet999:mainfrom
midwestcoder2020:main

Conversation

@midwestcoder2020

Copy link
Copy Markdown

Ported EventTranscription parsing to Golang. As of 2026 the following parsing query data sources don't seem to be located at the reported locations

W10 2026 No longer appear to be present:
WiFiConnectedEvents
SRUMAppActivity
WLANScanResults
SRUMNetworkUsageActivity

@AndrewRathbun

Copy link
Copy Markdown

Have you been seeing this artifact in the wild?

@midwestcoder2020

midwestcoder2020 commented Jun 12, 2026

Copy link
Copy Markdown
Author

still in Windows10 at the same general location as of June 2026. I believe some of the telemetry payloads have shifted a bit. But this is just providing a Golang port which will provide a performance improvement and add a little more language support.

@AndrewRathbun

Copy link
Copy Markdown

Yeah I get the intent of the PR but I was just interested to hear about if it was being leveraged in casework on the regular yet.

@midwestcoder2020

midwestcoder2020 commented Jun 12, 2026

Copy link
Copy Markdown
Author

Independent Researcher. The artifact is still in the wild. I believe CyberTriage have reported on it in the last year or so

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants