From 45baea8fe64428e635a6aa9969b855e8542a5d90 Mon Sep 17 00:00:00 2001 From: Lars Karlslund Date: Mon, 29 Nov 2021 11:33:53 +0100 Subject: [PATCH] Added recognized extensions to the readme --- readme.MD | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/readme.MD b/readme.MD index 74bbc5b..202185f 100644 --- a/readme.MD +++ b/readme.MD @@ -61,6 +61,11 @@ This will give you insight into who uses what systems, service accounts that are #### Analysis This is dead simple - everything you've collected should be in the data directory, either in the main folder or in subfolders. Whatever resides there and adalanche understands is automatically loaded, correlated and used. It's totally magic. +These extensions are recognized: +- .localmachine.json - Windows collector data +- .gpodata.json - Active Directory GPO data +- .objects.msgp.lz4 - Active Directory object/schema data in MsgPack format (LZ4 compressed) + Highly advanced command line to analyze and launch your browser: adalanche analyze