Skip to content

Commit d5b2f93

Browse files
authored
Merge pull request #1098 from AAtashGar/dataset/bitlocker
Add dataset for T1546.015 BitLocker COM Hijacking lateral movement
2 parents 7bf8726 + 7fbc838 commit d5b2f93

File tree

3 files changed

+23
-0
lines changed

3 files changed

+23
-0
lines changed
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
author: Ali Atashgar (AAtashGar)
2+
id: b8f4c2a1-9e7d-4f3b-8a1c-5d9e7f2b6a3e
3+
date: '2025-11-25'
4+
description: Simulated Windows Security and System events demonstrating the BitLocker Network Unlock COM Object Hijacking lateral movement technique (T1574.015 / T1546.015) using RemoteRegistry service enablement, HKCU CLSID manipulation, and execution via baaupdate.exe or BdeUISrv.exe.
5+
environment: NA
6+
directory: bitlocker_com_hijacking
7+
mitre_technique:
8+
- T1546.015
9+
datasets:
10+
- name: windows-security.log
11+
path: datasets/attack_techniques/T1546.015/bitlocker_com_hijacking/windows-security.log
12+
source: XmlWinEventLog:Security
13+
sourcetype: XmlWinEventLog
14+
- name: windows-system.log
15+
path: datasets/attack_techniques/T1546.015/bitlocker_com_hijacking/windows-system.log
16+
source: XmlWinEventLog:System
17+
sourcetype: XmlWinEventLog
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:bb99bf5fb415c94fa697ac1138158028fb03f350df587112c6d715bf43876761
3+
size 8856
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:5ebb20bfbf74c279370b775db9f2061296c9b0c52bc0092bb987750ef0f1525f
3+
size 1704

0 commit comments

Comments
 (0)