Skip to content

Commit d83efc4

Browse files
committed
adding datasets
1 parent 172e1d5 commit d83efc4

File tree

2 files changed

+6
-6
lines changed

2 files changed

+6
-6
lines changed

detections/network/detect_dns_query_to_decommissioned_s3_bucket.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,6 @@ tags:
5050
tests:
5151
- name: True Positive Test
5252
attack_data:
53-
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/dns_decommissioned_bucket/dns.log
54-
source: dns
55-
sourcetype: dns
53+
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/s3_bucket_deletion/s3_bucket_deletion.csv
54+
source: s3*
55+
sourcetype: aws:cloudtrail

detections/web/detect_web_access_to_decommissioned_s3_bucket.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,6 @@ tags:
5454
tests:
5555
- name: True Positive Test
5656
attack_data:
57-
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/web_decommissioned_bucket/proxy.log
58-
source: proxy
59-
sourcetype: web_proxy
57+
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/s3_bucket_deletion/s3_bucket_deletion.csv
58+
source: s3*
59+
sourcetype: aws:cloudtrail

0 commit comments

Comments
 (0)