We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent c38a06e commit 9284ab7Copy full SHA for 9284ab7
2 files changed
datasets/attack_techniques/T1218.011/rundll32_dll_in_temp/rundll32_dll_in_temp.yml
@@ -0,0 +1,11 @@
1
+author: Teoderick Contreras, Splunk
2
+id: 76f9a94c-6c63-11f0-89ae-629be3538068
3
+date: '2025-07-29'
4
+description: Generated datasets for rundll32 dll in temp in attack range.
5
+environment: attack_range
6
+dataset:
7
+- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/rundll32_dll_in_temp/rundll32_tmp.log
8
+sourcetypes:
9
+- 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
10
+references:
11
+- https://blog.sekoia.io/interlock-ransomware-evolving-under-the-radar/
datasets/attack_techniques/T1218.011/rundll32_dll_in_temp/rundll32_tmp.log
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:5ac4747551f733d673cd6828a55732b7b542d3552698325cbdac2df2a69aa62f
+size 4057
0 commit comments