Greetings and Thank You For This AWESOME Tool! Is it possible to obtain from the Windows Event Log Entry: 1. the **actual string** that matched from the Yara Rule that is written? In the screenshot below, I successfully am matching, but I would like to know how can the matched string be provided in the details. ## Writing the Test Yara Rule  <br/> ## Successfully Matching in Windows Log 
Greetings and Thank You For This AWESOME Tool!
Is it possible to obtain from the Windows Event Log Entry:
In the screenshot below, I successfully am matching, but I would like to know how can the matched string be provided in the details.
Writing the Test Yara Rule
Successfully Matching in Windows Log