Skip to content

Commit 441e9b1

Browse files
jwindleynasbench
andauthored
Add new test data for T1553.001 (#1109)
--------- Co-authored-by: Nasreddine Bencherchali <[email protected]>
1 parent fa62f08 commit 441e9b1

File tree

4 files changed

+32
-0
lines changed

4 files changed

+32
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:eed3cd1fcfd35b468a8326f4580800a64f54309121252111cd319d92f4329be7
3+
size 3352
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Jamie Windley
2+
id: bc5865ff-2ea2-4b78-b34b-f2b375d464a3
3+
date: '2025-12-16'
4+
description: Generated dataset for MacOS Gatekeeper Bypass using xattr
5+
environment: vm
6+
directory: macos_gatekeeper_bypass_xattr
7+
mitre_technique:
8+
- T1553.001
9+
datasets:
10+
- name: macos_gatekeeper_bypass_xattr.log
11+
path: /datasets/attack_techniques/T1553.001/atomic_red_team/macos_gatekeeper_bypass_xattr/macos_gatekeeper_bypass_xattr.log
12+
sourcetype: 'osquery:results'
13+
source: '/var/log/osquery/osqueryd.results.log'
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:2e2e29b722ab46aed1c4fb5c3c6a570ad298b10ef269d62c1b0c5fcf7d00b828
3+
size 1951
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Jamie Windley
2+
id: fbcfb4fb-1be3-4348-87d3-60c68a0b6334
3+
date: '2025-12-16'
4+
description: Generated dataset for MacOS Gatekeeper Bypass by making changes to LSFileQuarantineEnabled field in Info.plist
5+
environment: vm
6+
directory: macos_gatekeeper_bypass_LSFileQuarantineEnabled
7+
mitre_technique:
8+
- T1553.001
9+
datasets:
10+
- name: macos_gatekeeper_bypass_LSFileQuarantineEnabled.log
11+
path: /datasets/attack_techniques/T1553.001/macos_gatekeeper_bypass_LSFileQuarantineEnabled/macos_gatekeeper_bypass_LSFileQuarantineEnabled.log
12+
sourcetype: 'osquery:results'
13+
source: '/var/log/osquery/osqueryd.results.log'

0 commit comments

Comments
 (0)