Skip to content

Commit f9504ae

Browse files
committed
Add vmtoolsd execution
1 parent 81b7ee2 commit f9504ae

File tree

2 files changed

+14
-0
lines changed

2 files changed

+14
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:cdb0794700ffe957bbf8914768c60f43eaf3261c7c2f8c1c06d7c01e60f6be25
3+
size 2385
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Raven Tait, Splunk
2+
id: 45640c5f-9ef7-4d93-aa3e-2bc188d0be0a
3+
date: '2025-07-30'
4+
description: 'Sample of Sysmon events showing execution of commands on a host via VMWare Tools.'
5+
environment: custom
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/vmtoolsd_execution/vmtoolsd_execution.log
8+
sourcetypes:
9+
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10+
references:
11+
- https://attack.mitre.org/techniques/T1059

0 commit comments

Comments
 (0)