Skip to content

Commit c214808

Browse files
committed
secret_blizzard
1 parent 572fadd commit c214808

File tree

6 files changed

+42
-0
lines changed

6 files changed

+42
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:7b59305a325b7cc064ae1f5a4be1944d3db6070cb3775ec6583c36f8e676aaa5
3+
size 4542
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: eff617c0-72aa-11f0-9625-629be3538068
3+
date: '2025-08-06'
4+
description: Generated datasets for reg profiles private in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/reg_profiles_private/reg_profiles_private.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: e90865ba-72ac-11f0-9625-629be3538068
3+
date: '2025-08-06'
4+
description: Generated datasets for firewall api path in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.001/firewall_api_path/firewallapi_temp.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:2973ed09af8ca140f4c0da90d12a1399a2765428f6b4388df1f8876f45978d78
3+
size 1555
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 28f730ce-72ae-11f0-9625-629be3538068
3+
date: '2025-08-06'
4+
description: Generated datasets for add store cert in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1587.003/add_store_cert/addstore_cert.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:c31b0e86dd5ed796d2f2bcab64c479fe15a895bd0597961dc3746ad8603e4065
3+
size 4040

0 commit comments

Comments
 (0)