Skip to content

Commit 3b9588b

Browse files
author
Patrick Bareiss
committed
Add data.yml files
1 parent 6704d5f commit 3b9588b

File tree

771 files changed

+11015
-0
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

771 files changed

+11015
-0
lines changed
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
author: Generated by dataset_analyzer.py
2+
id: aebdb3f2-5df9-486b-8b73-87a9a5e51cc0
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory atomic_red_team
5+
environment: attack_range
6+
directory: atomic_red_team
7+
mitre_technique:
8+
- T1003.001
9+
datasets:
10+
- name: windows-sysmon_creddump
11+
path: /datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
14+
- name: procdump_windows-security
15+
path: /datasets/attack_techniques/T1003.001/atomic_red_team/procdump_windows-security.log
16+
sourcetype: XmlWinEventLog
17+
source: XmlWinEventLog:Security
18+
- name: crowdstrike_falcon
19+
path: /datasets/attack_techniques/T1003.001/atomic_red_team/crowdstrike_falcon.log
20+
sourcetype: crowdstrike:events:sensor
21+
source: crowdstrike
22+
- name: createdump_windows-sysmon
23+
path: /datasets/attack_techniques/T1003.001/atomic_red_team/createdump_windows-sysmon.log
24+
sourcetype: XmlWinEventLog
25+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
26+
- name: windows-sysmon
27+
path: /datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log
28+
sourcetype: XmlWinEventLog
29+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
author: Generated by dataset_analyzer.py
2+
id: c1560e15-24a3-41ef-8c8b-98caaa6d13cc
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory atomic_red_team
5+
environment: attack_range
6+
directory: atomic_red_team
7+
mitre_technique:
8+
- T1003.002
9+
datasets:
10+
- name: crowdstrike_falcon
11+
path: /datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
12+
sourcetype: crowdstrike:events:sensor
13+
source: crowdstrike
14+
- name: windows-sysmon
15+
path: /datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
16+
sourcetype: XmlWinEventLog
17+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Generated by dataset_analyzer.py
2+
id: 1805765d-d6b1-4877-bd35-9520939dae1f
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory detect_copy_of_shadowcopy_with_script_block_logging
5+
environment: attack_range
6+
directory: detect_copy_of_shadowcopy_with_script_block_logging
7+
mitre_technique:
8+
- T1003.002
9+
datasets:
10+
- name: windows-xml
11+
path: /datasets/attack_techniques/T1003.002/detect_copy_of_shadowcopy_with_script_block_logging/windows-xml.log
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Generated by dataset_analyzer.py
2+
id: 1a6789ed-c2ab-4937-939c-03eb41a8c653
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory serioussam
5+
environment: attack_range
6+
directory: serioussam
7+
mitre_technique:
8+
- T1003.002
9+
datasets:
10+
- name: windows-xml
11+
path: /datasets/attack_techniques/T1003.002/serioussam/windows-xml.log
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Security
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
author: Generated by dataset_analyzer.py
2+
id: 75688df7-5503-4cb0-9218-aa8951c11f39
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory atomic_red_team
5+
environment: attack_range
6+
directory: atomic_red_team
7+
mitre_technique:
8+
- T1003.003
9+
datasets:
10+
- name: crowdstrike_falcon
11+
path: /datasets/attack_techniques/T1003.003/atomic_red_team/crowdstrike_falcon.log
12+
sourcetype: crowdstrike:events:sensor
13+
source: crowdstrike
14+
- name: 4688_windows-security
15+
path: /datasets/attack_techniques/T1003.003/atomic_red_team/4688_windows-security.log
16+
sourcetype: XmlWinEventLog
17+
source: XmlWinEventLog:Security
18+
- name: windows-sysmon
19+
path: /datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log
20+
sourcetype: XmlWinEventLog
21+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Generated by dataset_analyzer.py
2+
id: c4b3c930-dbea-4a6c-a98f-5f26fd2bbabe
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory NoLMHash
5+
environment: attack_range
6+
directory: NoLMHash
7+
mitre_technique:
8+
- T1003.004
9+
datasets:
10+
- name: lsa-reg-settings-sysmon
11+
path: /datasets/attack_techniques/T1003.004/NoLMHash/lsa-reg-settings-sysmon.log
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Generated by dataset_analyzer.py
2+
id: e3e707b3-664d-4597-b749-f13cc8d3fdb5
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory impacket
5+
environment: attack_range
6+
directory: impacket
7+
mitre_technique:
8+
- T1003.006
9+
datasets:
10+
- name: windows-security-xml
11+
path: /datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Security
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Generated by dataset_analyzer.py
2+
id: c65ce500-ac9e-4f01-a4d1-7b59eef7c07c
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory mimikatz
5+
environment: attack_range
6+
directory: mimikatz
7+
mitre_technique:
8+
- T1003.006
9+
datasets:
10+
- name: xml-windows-security
11+
path: /datasets/attack_techniques/T1003.006/mimikatz/xml-windows-security.log
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Security
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Generated by dataset_analyzer.py
2+
id: 84ddc704-c5a6-4964-86c9-cc11cca6e530
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory copy_file_stdoutpipe
5+
environment: attack_range
6+
directory: copy_file_stdoutpipe
7+
mitre_technique:
8+
- T1003.008
9+
datasets:
10+
- name: sysmon_linux
11+
path: /datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log
12+
sourcetype: sysmon:linux
13+
source: Syslog:Linux-Sysmon/Operational
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
author: Generated by dataset_analyzer.py
2+
id: aacf4255-ce77-43da-9705-ad794ecccf61
3+
date: '2025-08-12'
4+
description: Automatically categorized datasets in directory linux_auditd_access_credential
5+
environment: attack_range
6+
directory: linux_auditd_access_credential
7+
mitre_technique:
8+
- T1003.008
9+
datasets:
10+
- name: auditd_proctitle_access_cred
11+
path: /datasets/attack_techniques/T1003.008/linux_auditd_access_credential/auditd_proctitle_access_cred.log
12+
sourcetype: auditd
13+
source: auditd
14+
- name: linux_auditd_access_credential
15+
path: /datasets/attack_techniques/T1003.008/linux_auditd_access_credential/linux_auditd_access_credential.log
16+
sourcetype: auditd
17+
source: auditd

0 commit comments

Comments
 (0)