Skip to content

Commit 76880c0

Browse files
authored
Merge pull request #961 from nterl0k/nterl0k-t1546-compattelrunner-abuse
Nterl0k - T1546 CompatTelRunner Abuse
2 parents 1878e5a + 5111ec6 commit 76880c0

File tree

2 files changed

+16
-0
lines changed

2 files changed

+16
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:cda644f8c240f802ab174acbf006da9e15ff91051d8a8dfa6d10793999f18805
3+
size 19166
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Steven Dick
2+
id: fcb9a608-5ccd-4106-a277-089d03277b0d
3+
date: '2025-02-10'
4+
description: 'Sample events for CompatTelRunner abuse.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/compattelrunner_abuse/compattelrunner_abuse.log
8+
sourcetypes:
9+
- XmlWinEventLog
10+
references:
11+
- https://attack.mitre.org/techniques/T1546/
12+
- https://scythe.io/threat-thursday/windows-telemetry-persistence
13+
- https://www.trustedsec.com/blog/abusing-windows-telemetry-for-persistence

0 commit comments

Comments
 (0)