Skip to content

Commit e4488c2

Browse files
committed
spus_proc_path
1 parent db21a62 commit e4488c2

File tree

2 files changed

+14
-0
lines changed

2 files changed

+14
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:e5d9dd394138305b60b75452ce71c2bcc508b8797e7e073267a1d431b141156b
3+
size 2014
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 2fa5d1b2-dc97-11ef-8b8c-acde48001122
3+
date: '2025-01-27'
4+
description: Generated datasets for suspicious process path in attack range.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/suspicious_process_path/susp_path_sysmon1.log
8+
sourcetypes:
9+
- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10+
references:
11+
- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat

0 commit comments

Comments
 (0)