Skip to content

Commit dd84cc5

Browse files
committed
add new datasets for rdp share and nirsoft
1 parent 6a6343a commit dd84cc5

File tree

4 files changed

+32
-0
lines changed

4 files changed

+32
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:0faecc0797d5b9c320965de44fa7d722abff0f8387df570f65da2e8cb7e7a923
3+
size 11222
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: 5b9f128a-50a1-469e-a806-6a89fd1b3076
3+
date: '2025-10-21'
4+
description: Generated datasets covering the creation or execution of NirSof ttooling.
5+
environment: attack_range
6+
directory: nirsoft_tooling
7+
mitre_technique:
8+
- T1021.001
9+
datasets:
10+
- name: execution_from_rdp_share.log
11+
path: /datasets/attack_techniques/T1021.001/execution_from_rdp_share/execution_from_rdp_share.log
12+
sourcetype: XmlWinEventLog
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:fbf6b1991701017cfe121dc2e5e137ed3b6a9c735376322864f90e4af97cf968
3+
size 4831
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: 5b9f127a-50a1-469e-a806-6a89fd1b3076
3+
date: '2025-10-21'
4+
description: Generated datasets covering the creation or execution of NirSof ttooling.
5+
environment: attack_range
6+
directory: nirsoft_tooling
7+
mitre_technique:
8+
- T1588.002
9+
datasets:
10+
- name: nirsoft_file_bundle_created.log
11+
path: /datasets/attack_techniques/T1588.002/nirsoft_tooling/nirsoft_file_bundle_created.log
12+
sourcetype: XmlWinEventLog
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'

0 commit comments

Comments
 (0)