Skip to content

Commit bb267d6

Browse files
committed
updating attack data yaml
1 parent 0028d39 commit bb267d6

File tree

1 file changed

+7
-8
lines changed

1 file changed

+7
-8
lines changed

datasets/cisco_isovalent/cisco_isovalent.yml

Lines changed: 7 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,10 @@ date: '2025-08-15'
44
description: Generated datasets for Cisco Isovalent Process Exec EventType. Contains simulations for the following detections:
55
* Cisco Isovalent - Detect Shell Execution
66
* Cisco Isovalent - Curl Execution With Insecure Flags
7-
dataset:
8-
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/cisco_isovalent/cisco_isovalent.log
9-
sourcetypes:
10-
- cisco:isovalent
11-
references:
12-
- https://docs.isovalent.com/operations-guide/tetragon/installation/helm.html
13-
- https://docs.isovalent.com/user-guide/sec-ops-visibility/index.html
14-
- https://isovalent.com/blog/post/isovalent-splunk-better-together/
7+
environment: manual simulations in a K8s cluster running Tetragon
8+
mitre_technique: []
9+
datasets:
10+
- name: cisco_isovalent
11+
path: /datasets/cisco_isovalent/cisco_isovalent.log
12+
sourcetype: cisco:isovalent
13+
source: cisco_isovalent

0 commit comments

Comments
 (0)