Skip to content

Commit f50b47b

Browse files
committed
update secure endpoint dataset
1 parent 5b2216f commit f50b47b

File tree

2 files changed

+5
-1
lines changed

2 files changed

+5
-1
lines changed

datasets/attack_techniques/T1562.001/cisco_secure_endpoint_tampering/cisco_secure_endpoint_tampering.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,11 @@
11
author: Nasreddine Bencherchali, Splunk
22
id: 98e9387e-4aab-4e59-8e17-2a33b74a8d69
33
date: '2025-01-08'
4-
description: Generated dataset for abusing the sfc.exe binary in order to tamper with Cisco Secure Endpoint.
4+
description: Generated dataset for abusing Cisco Secure Endpoint "sfc.exe" binary in order to tamper with Cisco Secure Endpoint services and features as well a dataset for tampering with Secure Endpoint services.
55
environment: attack_range
66
dataset:
77
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/cisco_secure_endpoint_tampering/sfc_tampering.log
8+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/cisco_secure_endpoint_tampering/service_stop.log
89
sourcetypes:
910
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1011
references:
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:4bc5b5685a35eeea435098ba176cf82366895ed5c85c155807aad834564b0079
3+
size 2343

0 commit comments

Comments
 (0)