Skip to content

Commit 8f56014

Browse files
committed
Merge branch 'master' into mirror_compressed_archive_to_s3
2 parents 00f9dfd + ef67bda commit 8f56014

File tree

55 files changed

+349
-6
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

55 files changed

+349
-6
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:7b0f24e6f490a5f59bb92aa09740b6f0d1b5898cca788f00aff5c3efb80199a3
3+
size 265569
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 05399f54-1ab2-11f0-a1c6-629be3538069
3+
date: '2025-04-16'
4+
description: Generated datasets for linux auditd net tool new in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/linux_auditd_net_tool_new/linux_auditd_net_tool_bucket_new.log
8+
sourcetypes:
9+
- 'auditd'
10+
references:
11+
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:cc26e035942fb454da59b44fb73ea95ddcc5abcb8f9fa739ab69dad15f0c3456
3+
size 716
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 7d0ae338-1aaf-11f0-a1c6-629be3538069
3+
date: '2025-04-16'
4+
description: Generated datasets for linux auditd split syscall new in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1030/linux_auditd_split_syscall_new/linux_auditd_new_split.log
8+
sourcetypes:
9+
- 'auditd'
10+
references:
11+
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:431929147fc4596b4e48f911a06543036a9c91546eacf10d00ad3b085afa8348
3+
size 1127
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 4cb6c050-1ab2-11f0-a1c6-629be3538069
3+
date: '2025-04-16'
4+
description: Generated datasets for linux auditd whoami new in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/linux_auditd_whoami_new/linux_auditd_new_whoami.log
8+
sourcetypes:
9+
- 'auditd'
10+
references:
11+
- https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:8f8a8fcd8664f1b2179686e42069bb1e6c0a11e69f0483d95ceec1f5185ba616
3+
size 3279
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: efcf229a-1aae-11f0-a1c6-629be3538069
3+
date: '2025-04-16'
4+
description: Generated datasets for linux new auditd at in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/linux_new_auditd_at/linux_auditd_new_at.log
8+
sourcetypes:
9+
- 'auditd'
10+
references:
11+
- https://www.linkedin.com/pulse/getting-attacker-ip-address-from-malicious-linux-job-craig-rowland/
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 4bed5528-1ab0-11f0-a1c6-629be3538069
3+
date: '2025-04-16'
4+
description: Generated datasets for linux auditd crontab edit new in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/linux_auditd_crontab_edit_new/linux_auditd_new_crontab.log
8+
sourcetypes:
9+
- 'auditd'
10+
references:
11+
- https://attack.mitre.org/techniques/T1053/003/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:85029e322d6526382d393a06fa1b08263d673774c6060805c4a9fe5c9db5fe15
3+
size 1116

0 commit comments

Comments
 (0)