File tree Expand file tree Collapse file tree 2 files changed +14
-0
lines changed
datasets/attack_techniques/T1531/powershell_log_process_tree Expand file tree Collapse file tree 2 files changed +14
-0
lines changed Original file line number Diff line number Diff line change 1+ author : Teoderick Contreras, Splunk
2+ id : 844d92ee-bc81-11ef-82f7-acde48001122
3+ date : ' 2024-12-17'
4+ description : Generated datasets for powershell log process tree in attack range.
5+ environment : attack_range
6+ dataset :
7+ - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/powershell_log_process_tree/powershell_logoff.log
8+ sourcetypes :
9+ - ' XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+ references :
11+ - https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/
Original file line number Diff line number Diff line change 1+ version https://git-lfs.github.com/spec/v1
2+ oid sha256:23b545c90a61d5712c6a815a3bf45257eebfd8404b35affca5ace71ee548f2f8
3+ size 12255
You can’t perform that action at this time.
0 commit comments