Skip to content

Commit da34cad

Browse files
authored
Merge pull request #931 from nterl0k/nterl0k-t1033-query-remote-usage
Nterl0k - T1033 Query.exe on Remote Devices
2 parents cef9eca + 9ff045c commit da34cad

File tree

2 files changed

+15
-0
lines changed

2 files changed

+15
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:c0abb08c7fd7ef9a21251f059932a16813c2fdad9c6cb05a0389fcd6aa166820
3+
size 8122
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Steven Dick
2+
id: d5ce6a18-1de6-4351-9148-f81d47ae2a44
3+
date: '2025-01-06'
4+
description: 'A set of events related the usage of query.exe on remote devices.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/query_remote_usage/query_remote_usage.log
8+
sourcetypes:
9+
- XmlWinEventLog
10+
references:
11+
- https://attack.mitre.org/techniques/T1033/
12+
- https://blog.bitsadmin.com/living-off-the-foreign-land-windows-as-offensive-platform-part-3

0 commit comments

Comments
 (0)