Skip to content

Commit 81b7ee2

Browse files
committed
rdp
1 parent 9284ab7 commit 81b7ee2

File tree

18 files changed

+126
-0
lines changed

18 files changed

+126
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:02509f46c0827bf20cab033da354191ec78f76f78cee88ab469b800efa816089
3+
size 1092
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 2050c38a-6d1e-11f0-86b8-629be3538068
3+
date: '2025-07-30'
4+
description: Generated datasets for bmc creation in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.001/bmc_creation/bmc_creation.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://medium.com/@bonguides25/how-to-clear-rdp-connections-history-in-windows-cf0ffb67f344
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:2b4e043ffb2a24d2da86e1ef9b396fc53cc8169d4974434057d4d1a802eb7540
3+
size 19709
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: bf432e34-6d3b-11f0-86b8-629be3538068
3+
date: '2025-07-30'
4+
description: Generated datasets for mstsc admini in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.001/mstsc_admini/mstsc_admin.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://medium.com/@bonguides25/how-to-clear-rdp-connections-history-in-windows-cf0ffb67f344
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:48db5e0511cab2055386df33d44309cc03fc81f61292ce939d2ceef18d8443a5
3+
size 1048
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 30e07cc0-6d25-11f0-86b8-629be3538068
3+
date: '2025-07-30'
4+
description: Generated datasets for rdp creation in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.001/rdp_creation/deafault_rdp_created.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://medium.com/@bonguides25/how-to-clear-rdp-connections-history-in-windows-cf0ffb67f344
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 27f7e43a-6d3a-11f0-86b8-629be3538068
3+
date: '2025-07-30'
4+
description: Generated datasets for terminal server reg created in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.001/terminal_server_reg_created/terminal_sever_client_Reg_created.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://medium.com/@bonguides25/how-to-clear-rdp-connections-history-in-windows-cf0ffb67f344
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:5342e02893436798ee664d51b0c19098a395b99039e208d4e5e7f6f530cf6c82
3+
size 8021
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:e01d3f22c954a724a0ce81fc3537dedc15a33699315190fecca6303390d0dc44
3+
size 24073
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: a2d674e4-6d3c-11f0-86b8-629be3538068
3+
date: '2025-07-30'
4+
description: Generated datasets for unhide file in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.001/unhide_file/unhide_file.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://medium.com/@bonguides25/how-to-clear-rdp-connections-history-in-windows-cf0ffb67f344

0 commit comments

Comments
 (0)