Skip to content

Commit 6abeddf

Browse files
authored
Merge pull request #1031 from splunk/lokibot
lokibot
2 parents 82f1235 + fdde6ec commit 6abeddf

File tree

3 files changed

+18
-0
lines changed

3 files changed

+18
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:57edefcbfadbe1954fa2867cbf5ad761e0f1a16097f9926d95c515358bc29f44
3+
size 8696
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 489169c0-9ea7-11f0-ba06-629be353806a
3+
date: '2025-10-01'
4+
description: Generated datasets for vbc dnsquery in attack range.
5+
environment: attack_range
6+
directory: vbc_dnsquery
7+
mitre_technique:
8+
- T1071.004
9+
datasets:
10+
- name: vbc_dns_query.log
11+
path: /datasets/attack_techniques/T1071.004/vbc_dnsquery/vbc_dns_query.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'

datasets/m365_copilot/m365_copilot.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ id: 0bf90131-c582-4976-85b8-711d2c2c1926
33
date: '2025-09-25'
44
description: |
55
Logs from M365 Copilot Access Logs via Splunk Add-on for M365 and Exported Logs from eDsicovery Purview. Contains actual access logs and jailbreak attacks.
6+
environment: attack_range
7+
directory: m365_copilot
68
mitre_technique: []
79
datasets:
810
- name: m365_access_logs

0 commit comments

Comments
 (0)