Skip to content

Commit 572fadd

Browse files
committed
Add medusa logs
1 parent e31e0fa commit 572fadd

File tree

3 files changed

+17
-2
lines changed

3 files changed

+17
-2
lines changed
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Raven Tait, Splunk
2+
id: 2481e83c-b888-4383-bc61-9d292f4e03ea
3+
date: '2025-08-05'
4+
description: Logs from usage of the Medusa rootkit on a Linux host.
5+
environment: custom
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1014/medusa_rootkit/sysmon_linux.log
8+
sourcetypes:
9+
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10+
- Syslog:Linux-Sysmon/Operational
11+
references:
12+
- https://attack.mitre.org/techniques/T1014/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:092f23c31aaa9c2f26d38c083255ade96bd953e0b5110443e9c1d39ae487bf63
3+
size 6275
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
version https://git-lfs.github.com/spec/v1
2-
oid sha256:9d4131e5da55ad18265a03de96a248ff3f0193e56e148c8cbc38423cc41975f6
3-
size 5546
2+
oid sha256:f06508f6810bcfc183393448f973db7185e0059fc1b716e45fe42cd620b9d701
3+
size 5545

0 commit comments

Comments
 (0)