File tree Expand file tree Collapse file tree 2 files changed +16
-0
lines changed
datasets/attack_techniques/T1546/adminsdholder_modified/compattelrunner_abuse Expand file tree Collapse file tree 2 files changed +16
-0
lines changed Original file line number Diff line number Diff line change 1+ version https://git-lfs.github.com/spec/v1
2+ oid sha256:cda644f8c240f802ab174acbf006da9e15ff91051d8a8dfa6d10793999f18805
3+ size 19166
Original file line number Diff line number Diff line change 1+ author : Steven Dick
2+ id : fcb9a608-5ccd-4106-a277-089d03277b0d
3+ date : ' 2025-02-10'
4+ description : ' Sample events for CompatTelRunner abuse.'
5+ environment : attack_range
6+ dataset :
7+ - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/compattelrunner_abuse/compattelrunner_abuse.log
8+ sourcetypes :
9+ - XmlWinEventLog
10+ references :
11+ - https://attack.mitre.org/techniques/T1546/
12+ - https://scythe.io/threat-thursday/windows-telemetry-persistence
13+ - https://www.trustedsec.com/blog/abusing-windows-telemetry-for-persistence
You can’t perform that action at this time.
0 commit comments