Skip to content

Commit 80a31d0

Browse files
authored
Merge pull request #1013 from splunk/speechruntime
Add dataset for SpeechRuntime Hijacking
2 parents 0db79c3 + 112145d commit 80a31d0

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Raven Tait, Splunk
2+
id: 54417fe2-a9c5-46f8-895a-591f5d87231e
3+
date: '2025-08-25'
4+
description: Using DLL to start a process on a remote endpoint
5+
leveraging COM Hijacking against SpeechRuntime to perform lateral movement and remote code execution.
6+
environment: attack_range
7+
directory: lateral_movement_speechruntime
8+
mitre_technique:
9+
- T1021.003
10+
datasets:
11+
- name: windows-sysmon
12+
path: /datasets/attack_techniques/T1021.003/lateral_movement_speechruntime/windows-sysmon.log
13+
sourcetype: XmlWinEventLog
14+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:cf3358ff725498d5371cc79967539a435aaf46b2c6fb4c944ebab61fccdf63ef
3+
size 6525

0 commit comments

Comments
 (0)