File tree Expand file tree Collapse file tree 4 files changed +22
-5
lines changed
datasets/attack_techniques
T1053/hidden_schedule_task Expand file tree Collapse file tree 4 files changed +22
-5
lines changed Original file line number Diff line number Diff line change 1- author : Teoderick Contreras
2- id : bd48efd0-c611-11ec-a219-acde48001122
3- date : ' 2022-04-27 '
1+ author : Teoderick Contreras, Splunk
2+ id : 59d45fb2-3a11-11f0-9e8a-629be3538068
3+ date : ' 2025-05-26 '
44description : Generated datasets for hidden schedule task in attack range.
55environment : attack_range
66dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053/hidden_schedule_task/security .log
7+ - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053/hidden_schedule_task/inno_schtask .log
88sourcetypes :
9- - WinEventLog :Security
9+ - ' XmlWinEventLog :Security'
1010references :
1111- https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
Original file line number Diff line number Diff line change 1+ version https://git-lfs.github.com/spec/v1
2+ oid sha256:5f34e3159b9808e43f41b508d78971ae21a84e89fec10622be1d9f74a8c28f47
3+ size 9428
Original file line number Diff line number Diff line change 1+ author : Teoderick Contreras, Splunk
2+ id : 842a3076-3a15-11f0-9e8a-629be3538068
3+ date : ' 2025-05-26'
4+ description : Generated datasets for chrom no sandbox in attack range.
5+ environment : attack_range
6+ dataset :
7+ - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1497/chrom_no_sandbox/chrome-no_sandbox.log
8+ sourcetypes :
9+ - ' XmlWinEventLog:Security'
10+ references :
11+ - https://unix.stackexchange.com/questions/68832/what-does-the-chromium-option-no-sandbox-mean
Original file line number Diff line number Diff line change 1+ version https://git-lfs.github.com/spec/v1
2+ oid sha256:8d407e5c516063f267694431f34640fa60c9c98f32449f0fcb74ad55904dd0a2
3+ size 7166
You can’t perform that action at this time.
0 commit comments