Skip to content

Commit 69fa8ae

Browse files
blankgrabber (#1140)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
1 parent 9fb07c7 commit 69fa8ae

File tree

12 files changed

+96
-0
lines changed

12 files changed

+96
-0
lines changed
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: af95e1a6-196c-11f1-a72e-629be353806a
3+
date: '2026-03-06'
4+
description: Generated datasets for backup product key registry in attack range.
5+
environment: attack_range
6+
directory: backup_product_key_registry
7+
mitre_technique:
8+
- T1012
9+
datasets:
10+
- name: backup_protection.log
11+
path: /datasets/attack_techniques/T1012/backup_product_key_registry/backup_protection.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Security'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:2b6423cb2660be00a9372e68e3cf380581c4cb85fae3fc3492261dea9de3675e
3+
size 1254
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 1248c214-196d-11f1-a72e-629be353806a
3+
date: '2026-03-06'
4+
description: Generated datasets for host file accessed in attack range.
5+
environment: attack_range
6+
directory: host_file_accessed
7+
mitre_technique:
8+
- T1012
9+
datasets:
10+
- name: hosts_accessed.log
11+
path: /datasets/attack_techniques/T1012/host_file_accessed/hosts_accessed.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Security'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:dab0cef35984e303f3a480ff3919663597468c143c4db0f1103e07122d180f63
3+
size 15393
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:57d7d9159fb48e074cd2954cbb2778ec1276502e9ca0bcd64d8f89cedea90fb4
3+
size 4342
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: ebd77fee-196c-11f1-a72e-629be353806a
3+
date: '2026-03-06'
4+
description: Generated datasets for susp winrar in attack range.
5+
environment: attack_range
6+
directory: susp_winrar
7+
mitre_technique:
8+
- T1047
9+
datasets:
10+
- name: blank123.log
11+
path: /datasets/attack_techniques/T1047/susp_winrar/blank123.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 8188a806-196d-11f1-a72e-629be353806a
3+
date: '2026-03-06'
4+
description: Generated datasets for wmic classes in attack range.
5+
environment: attack_range
6+
directory: wmic_classes
7+
mitre_technique:
8+
- T1047
9+
datasets:
10+
- name: wmic_cmd.log
11+
path: /datasets/attack_techniques/T1047/wmic_classes/wmic_cmd.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:4d4894fe9a4d6bc11315788d0cd4f83e5865a7fbb7be9c2441eedd451fe4f8e5
3+
size 16015
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:fc4a25a46ac4e5dda18b601403c81068905eb52197af6d32ac1c75242b398f17
3+
size 2083
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: f5d8301e-196d-11f1-a72e-629be353806a
3+
date: '2026-03-06'
4+
description: Generated datasets for upload files dns in attack range.
5+
environment: attack_range
6+
directory: upload_files_dns
7+
mitre_technique:
8+
- T1071.004
9+
datasets:
10+
- name: upload_files.log
11+
path: /datasets/attack_techniques/T1071.004/upload_files_dns/upload_files.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'

0 commit comments

Comments
 (0)