Skip to content

Commit cc4fab4

Browse files
authored
Merge pull request #1051 from splunk/add-oracle-b64
add oracle and pwsh b64
2 parents d6231c9 + 0d1da8e commit cc4fab4

File tree

4 files changed

+32
-0
lines changed

4 files changed

+32
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:578c02d29fd3b8eec51f9603dd5267636bad190d2c091aaf7f34b8c4e32f5e4c
3+
size 28882
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: 2d2d0452-1d37-4f73-8e58-c2f0c57de465
3+
date: '2025-10-23'
4+
description: Generated datasets covering the manual Base64 decoding using PowerShell.
5+
environment: attack_range
6+
directory: manual_b64_decode_pwsh
7+
mitre_technique:
8+
- T1027.010
9+
datasets:
10+
- name: nirsoft_file_bundle_created.log
11+
path: /datasets/attack_techniques/T1027.010/manual_b64_decode_pwsh/manual_b64_decode_pwsh.log
12+
sourcetype: XmlWinEventLog
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:a9613ad58cdd000f352ea5caa7277095a8c12f6563e287e231105c65c16178f6
3+
size 18032
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: 57776d92-b6db-4bf1-9dd2-e81702059f8e
3+
date: '2025-10-23'
4+
description: Generated a fake dataset manually for snort triggers generated by an FTD covering the potential exploitation of Oracle E-Business Suite CVE-2025-61882 and CVE-2025-61884.
5+
environment: custom
6+
directory: oracle_e_business_suite
7+
mitre_technique:
8+
- T1190
9+
datasets:
10+
- name: nirsoft_file_bundle_created.log
11+
path: /datasets/attack_techniques/T1027.010/oracle_e_business_suite/oracle_e_business_suite.log
12+
sourcetype: cisco:sfw:estreamer
13+
source: not_applicable

0 commit comments

Comments
 (0)