File tree Expand file tree Collapse file tree 2 files changed +17
-0
lines changed
datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name Expand file tree Collapse file tree 2 files changed +17
-0
lines changed Original file line number Diff line number Diff line change 1+ version https://git-lfs.github.com/spec/v1
2+ oid sha256:4af0e2d1b8dfae2e6e7cd18dcb85db50a028effc8d46f9fe3cfc21b633b2e6c0
3+ size 3373
Original file line number Diff line number Diff line change 1+ author : Steven Dick
2+ id : ea908665-bc39-4493-a20a-041543ba4f3b
3+ date : ' 2025-01-28'
4+ description : ' A sample event with a known malicous Task Name.'
5+ environment : attack_range
6+ dataset :
7+ - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.log
8+ sourcetypes :
9+ - XmlWinEventLog
10+ references :
11+ - https://attack.mitre.org/techniques/T1053/005/
12+ - https://www.ic3.gov/CSA/2023/231213.pdf
13+ - https://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/
14+ - https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_windows_tasks_list.csv
You can’t perform that action at this time.
0 commit comments