Skip to content

Commit dff8e1f

Browse files
added data source for new technique of attack
1 parent fc0bae5 commit dff8e1f

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
{"type": "PATH","msg": "audit(1747951721.229:634)","item": 1,"name": "/proc/sysrq-trigger","inode": 4026532271,"dev": "00:19","mode": "0100200","ouid": 0,"ogid": 0,"rdev": "00:00","nametype": "NORMAL","cap_fp": 0,"cap_fi": 0,"cap_fe": 0,"cap_fver": 0,"cap_frootid": 0,"OUID": "root","OGID": "root"}
2+
{"type": "PATH","msg": "audit(1747951721.494:677)","item": 1,"name": "/proc/sysrq-trigger","inode": 4026532271,"dev": "00:19","mode": "0100200","ouid": 0,"ogid": 0,"rdev": "00:00","nametype": "NORMAL","cap_fp": 0,"cap_fi": 0,"cap_fe": 0,"cap_fver": 0,"cap_frootid": 0,"OUID": "root","OGID": "root"}
3+
{"type": "PATH","msg": "audit(1747951721.234:699)","item": 1,"name": "/proc/sysrq-trigger","inode": 4026532271,"dev": "00:19","mode": "0100200","ouid": 0,"ogid": 0,"rdev": "00:00","nametype": "NORMAL","cap_fp": 0,"cap_fi": 0,"cap_fe": 0,"cap_fver": 0,"cap_frootid": 0,"OUID": "root","OGID": "root"}
4+
{"type": "PATH","msg": "audit(1747951721.546:712)","item": 1,"name": "/proc/sysrq-trigger","inode": 4026532271,"dev": "00:19","mode": "0100200","ouid": 0,"ogid": 0,"rdev": "00:00","nametype": "NORMAL","cap_fp": 0,"cap_fi": 0,"cap_fe": 0,"cap_fver": 0,"cap_frootid": 0,"OUID": "root","OGID": "root"}
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Milad Cheraghi
2+
id: b4b1271b-4529-4f36-9edc-d70765eaa4c0
3+
date: '2025-08-28'
4+
description: 'Sample of Linux auditd events showing potential abuse of the Magic SysRq key to manipulate or destabilize the system.'
5+
environment: custom
6+
directory: linux_sysrq_abuse
7+
mitre_technique:
8+
- T1529
9+
datasets:
10+
- name: linux-auditd
11+
path: /datasets/attack_techniques/T1529/linux_sysrq_abuse/linux_sysrq_abuse.log
12+
sourcetype: auditd
13+
source: auditd

0 commit comments

Comments
 (0)