Skip to content

Commit ae0c223

Browse files
authored
Merge pull request #1025 from splunk/expand
Expand Sysmon
2 parents 297a53b + 999ddf3 commit ae0c223

File tree

2 files changed

+11
-4
lines changed

2 files changed

+11
-4
lines changed

datasets/attack_techniques/T1140/atomic_red_team/atomic_red_team.yml

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,11 @@ directory: atomic_red_team
88
mitre_technique:
99
- T1140
1010
datasets:
11-
- name: windows-sysmon
12-
path: /datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log
13-
sourcetype: XmlWinEventLog
14-
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
- name: windows-sysmon
12+
path: /datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log
13+
sourcetype: XmlWinEventLog
14+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
15+
- name: expand_windows-sysmon
16+
path: /datasets/attack_techniques/T1140/atomic_red_team/expand_windows-sysmon.log
17+
sourcetype: XmlWinEventLog
18+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:183204efd8001f652380ba1ae77789782e5934b1e5ffc7c079bb346bbb049342
3+
size 31869

0 commit comments

Comments
 (0)