Skip to content

Commit 4eea3c5

Browse files
authored
Merge pull request #958 from nterl0k/nterl0k-t1053-windows-suspicious-task-lookups
Nterl0k - T1053 Windows Suspicious Task Lookup
2 parents 594c96c + 673a1f8 commit 4eea3c5

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:4af0e2d1b8dfae2e6e7cd18dcb85db50a028effc8d46f9fe3cfc21b633b2e6c0
3+
size 3373
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Steven Dick
2+
id: ea908665-bc39-4493-a20a-041543ba4f3b
3+
date: '2025-01-28'
4+
description: 'A sample event with a known malicous Task Name.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.log
8+
sourcetypes:
9+
- XmlWinEventLog
10+
references:
11+
- https://attack.mitre.org/techniques/T1053/005/
12+
- https://www.ic3.gov/CSA/2023/231213.pdf
13+
- https://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/
14+
- https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_windows_tasks_list.csv

0 commit comments

Comments
 (0)