Skip to content

Commit f2bbebd

Browse files
authored
Merge pull request #922 from nterl0k/nterl0k-t1595-generic-scanning
nterl0k - T1595 - Generic Scanning Behavior
2 parents 60fef3b + d503e8e commit f2bbebd

File tree

2 files changed

+14
-0
lines changed

2 files changed

+14
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:40a7d79315b446abe7d9d81a1f7d26a7c55006b623fe420b2dc78954424a2d79
3+
size 92180
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Steven Dick
2+
id: 981a2657-3ed0-46e9-b9f4-8a59a6442cb3
3+
date: '2024-12-26'
4+
description: 'A set of events related generic powershell/sysmon network enumeration.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/sysmon_scanning_events/sysmon_scanning_events.log
8+
sourcetypes:
9+
- XmlWinEventLog
10+
references:
11+
- https://attack.mitre.org/techniques/T1595

0 commit comments

Comments
 (0)