Skip to content

Commit fd9ba66

Browse files
author
Patrick Bareiss
committed
Cisco Duo dataset
1 parent eeac34f commit fd9ba66

File tree

22 files changed

+154
-0
lines changed

22 files changed

+154
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:efb0188ba7bca7fa541230f7d1c778ecfb25ebfca7e34767b46e528a9fdfc2de
3+
size 916
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Patrick Bareiss
2+
id: 01167925-4c70-4c62-a850-54c3da8ed54e
3+
date: '2025-07-10'
4+
description: 'Deleted multiple policies in Duo.'
5+
environment: Cisco Duo Tenant
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/cisco_duo_bulk_policy_deletion/cisco_duo_administrator.json
8+
sourcetypes:
9+
- cisco:duo:administrator
10+
references:
11+
- https://attack.mitre.org/techniques/T1556/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:8701e9be8bef7d2802e1d82899c51c9de4feda793bbbd8f54480ebbc92adf1d6
3+
size 2765
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Patrick Bareiss
2+
id: 27cc5ad7-1afd-4409-863e-9fac6f4cf941
3+
date: '2025-07-08'
4+
description: 'Changed the setting for a user to allow them to bypass 2FA in Duo.'
5+
environment: Cisco Duo Tenant
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/cisco_duo_bypass_2FA/cisco_duo_activity.json
8+
sourcetypes:
9+
- cisco:duo:activity
10+
references:
11+
- https://attack.mitre.org/techniques/T1556/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:858d3cfb2f5ad7dfb9f02b8fa37c60a8bb8b923a26a2d15082991d02ac0d2189
3+
size 1119
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Patrick Bareiss
2+
id: 876dbd42-57bb-40dc-a61f-269b6b6f6a4a
3+
date: '2025-07-08'
4+
description: 'Generate a bypass code for a user in Duo.'
5+
environment: Cisco Duo Tenant
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/cisco_duo_bypass_code/cisco_duo_activity.json
8+
sourcetypes:
9+
- cisco:duo:administrator
10+
references:
11+
- https://attack.mitre.org/techniques/T1556/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:5c5aebd7d22c939949ea0f673ffdf1aeccbd2902b550447291c68835435326ba
3+
size 425
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Patrick Bareiss
2+
id: 61a63676-89fe-4c8a-aa62-f0cf0e917837
3+
date: '2025-07-10'
4+
description: 'Created a policy which allows devices without screen lock in Duo.'
5+
environment: Cisco Duo Tenant
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/cisco_duo_policy_allow_devices_without_screen_lock/cisco_duo_administrator.json
8+
sourcetypes:
9+
- cisco:duo:administrator
10+
references:
11+
- https://attack.mitre.org/techniques/T1556/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:9665b55655c437d63bace9e1d299e6664100c87c6e7ef6d4423ca9ccf100062b
3+
size 955
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Patrick Bareiss
2+
id: db6c74e0-aaac-4bd2-b557-d2327746d105
3+
date: '2025-07-09'
4+
description: 'Created a policy which allow network bypass 2FA in Duo.'
5+
environment: Cisco Duo Tenant
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/cisco_duo_policy_allow_network_bypass_2fa/cisco_duo_administrator.json
8+
sourcetypes:
9+
- cisco:duo:administrator
10+
references:
11+
- https://attack.mitre.org/techniques/T1556/

0 commit comments

Comments
 (0)