Skip to content

Commit 5a336f8

Browse files
committed
Merge branch 'master' into mirror_compressed_archive_to_s3
2 parents a64194a + ca073f2 commit 5a336f8

20 files changed

+50
-17
lines changed

datasets/attack_techniques/T1059.001/encoded_powershell/encoded_powershell.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ environment: attack_range
66
dataset:
77
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log
88
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-security.log
9+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/padded_windows-sysmon.log
10+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/explorer_spawns_windows-sysmon.log
911
sourcetypes:
1012
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1113
references:
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:9200692ad74037b5234fe6f7da733d3e416b0ea8bb7f6d8ebb5bd16fc39b8b22
3+
size 13142
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:0324ee4e5f2cb4c761e10862808c37a046097a2ad800d034490e3980c3e86dec
3+
size 11135
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Michael Haag, Splunk
2+
id: 9535ef60-d182-212c-bxbb-6d1bd61e83be
3+
date: '2025-03-26'
4+
description: Manual generation of attack data related to Tomcat with nginx proxypass.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/tomcat/tomcat_nginx_access.log
8+
sourcetypes:
9+
- nginx:plus:kv
10+
references:
11+
- https://attack.mitre.org/techniques/T1190
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:752e19d3a09418f7d2ebbf779f54ed7d1127045f7023138176f33e189ed28536
3+
size 29219

datasets/attack_techniques/T1562.004/firewall_win_event/MPSSVC_Rule-Level_Policy_Change-4946.log.txt

Lines changed: 0 additions & 3 deletions
This file was deleted.

datasets/attack_techniques/T1562.004/firewall_win_event/MPSSVC_Rule-Level_Policy_Change-4947.log.txt

Lines changed: 0 additions & 1 deletion
This file was deleted.

datasets/attack_techniques/T1562.004/firewall_win_event/MPSSVC_Rule-Level_Policy_Change-4948.log.txt

Lines changed: 0 additions & 2 deletions
This file was deleted.
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:3f712cfe84c2aa58513654cafe8355be921aa7436fa9ad9782a9c80575b29624
3+
size 2371

datasets/attack_techniques/T1562.004/firewall_win_event/added_rule/MPSSVC_Rule-Level_Policy_Change-4946.log.txt

Lines changed: 0 additions & 3 deletions
This file was deleted.

0 commit comments

Comments
 (0)