Skip to content

Commit fdb3a3b

Browse files
author
Patrick Bareiss
committed
Merge branch 'master' into data_source_improvement
2 parents 779af00 + daace9f commit fdb3a3b

File tree

95 files changed

+646
-2
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

95 files changed

+646
-2
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:880d7e97db26dbccde3101f25416bf70b743238de17fe1c409c951a58baf2229
3+
size 1271
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Raven Tait, Splunk
2+
id: f4e7c8fc-c534-415b-9f99-9e9419096db5
3+
date: '2025-07-09'
4+
description: 'Sample of ESXi syslog events showing attempts to access sensitive files on the ESXi system.'
5+
environment: custom
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/esxi_sensitive_files/esxi_sensitive_files.log
8+
sourcetypes:
9+
- vmw-syslog
10+
references:
11+
- https://attack.mitre.org/techniques/T1003/008
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:a50666c61f331226509ef462349fc891e46caaad70b1767422aee048f664acef
3+
size 271
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Raven Tait, Splunk
2+
id: 6cbe3ac7-510d-49ab-983e-7ee504d6f386
3+
date: '2025-07-09'
4+
description: 'Sample of ESXi syslog events showing downloading of VMs from ESXi using remote tools."
5+
environment: custom
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1005/esxi_vm_download/esxi_vm_download.log
8+
sourcetypes:
9+
- vmw-syslog
10+
references:
11+
- https://attack.mitre.org/techniques/T1005
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Raven Tait, Splunk
2+
id: 2481e83c-b888-4383-bc61-9d292f4e03ea
3+
date: '2025-08-05'
4+
description: Logs from usage of the Medusa rootkit on a Linux host.
5+
environment: custom
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1014/medusa_rootkit/sysmon_linux.log
8+
sourcetypes:
9+
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10+
- Syslog:Linux-Sysmon/Operational
11+
references:
12+
- https://attack.mitre.org/techniques/T1014/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:092f23c31aaa9c2f26d38c083255ade96bd953e0b5110443e9c1d39ae487bf63
3+
size 6275
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:2b207c84b6b322daf28e27086831fcc0eb7090d1caa438f64c009fa5745de725
3+
size 8415
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Jamie Windley
2+
id: e0c0d5e5-8c29-4db3-9d27-d42f31c552f5
3+
date: '2025-08-15'
4+
description: Generated datasets for MacOS net discovery
5+
environment: vm
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/atomic_red_team/macos_net_discovery/macos_list_firewall_rules.log
8+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/atomic_red_team/macos_net_discovery/macos_network_discovery.log
9+
sourcetypes:
10+
- osquery:results
11+
references:
12+
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1016/T1016.md
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:b5687df76db37a6faf7a8509e88d0cd1820c23e64fff4d92a580d74bf9c996b0
3+
size 5022
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:02509f46c0827bf20cab033da354191ec78f76f78cee88ab469b800efa816089
3+
size 1092

0 commit comments

Comments
 (0)