Skip to content

Commit ec7b71e

Browse files
authored
Merge pull request #1062 from splunk/wsus
WSUS CVE-2025-59287
2 parents d032d32 + 68bf516 commit ec7b71e

File tree

2 files changed

+8
-1
lines changed

2 files changed

+8
-1
lines changed

datasets/attack_techniques/T1505.003/T1505.003.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
author: Michael Haag
22
id: cc9b2609-efc9-11eb-926b-550bf0943fbb
3-
date: '2021-03-11'
3+
date: '2025-10-24'
44
description: The following data was produced to emulate IIS, w3wp.exe, spawning shells,
55
simulating web shell activity. In addition, behavior related to Microsoft Exchange
66
Server's Unified Messaging services, umworkerprocess.exe and umservice.exe, spawning
@@ -28,3 +28,7 @@ datasets:
2828
path: /datasets/attack_techniques/T1505.003/moveit_windows-sysmon.log
2929
sourcetype: XmlWinEventLog
3030
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
31+
- name: wsus-windows-sysmon
32+
path: /datasets/attack_techniques/T1505.003/wsus-windows-sysmon.log
33+
sourcetype: XmlWinEventLog
34+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:f9a4be69d25d2c39be02a4288f75780b4e34a80d3555a8900e4f7a3c977ec220
3+
size 13290

0 commit comments

Comments
 (0)