Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Difference between GET and WHERE #249

Open
subbyte opened this issue Aug 11, 2022 · 0 comments
Open

Difference between GET and WHERE #249

subbyte opened this issue Aug 11, 2022 · 0 comments
Labels
documentation Improvements or additions to documentation

Comments

@subbyte
Copy link
Member

subbyte commented Aug 11, 2022

There is an interesting difference that hasn't been documented. May need to clarify this in doc.

x = GET process FROM stixshifter://hostA WHERE [process:name = 'cmd.exe']

# the following will do a prefetch
y = GET process FROM x WHERE [process:command_line = 'cmd.exe test']

# the following will not do prefetch
z = x WHERE command_line = 'cmd.exe test'
@subbyte subbyte added the documentation Improvements or additions to documentation label Aug 11, 2022
@subbyte subbyte added this to the Parser upgrade milestone Oct 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

1 participant