Skip to content

Commit b2e4041

Browse files
authored
Merge pull request #1145 from splunk/gh0st
gh0st
2 parents 24672bc + 9b89fb9 commit b2e4041

File tree

4 files changed

+32
-0
lines changed

4 files changed

+32
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:6dcdb8e7f63ec337464ed69e3e2e197d9bda49339f33c903fc111189ac253d4f
3+
size 5484
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: cd569370-2768-11f1-9dd5-629be353806a
3+
date: '2026-03-24'
4+
description: Generated datasets for remote access reg in attack range.
5+
environment: attack_range
6+
directory: remote_access_reg
7+
mitre_technique:
8+
- T1112
9+
datasets:
10+
- name: remote_access_reg.log
11+
path: /datasets/attack_techniques/T1112/remote_access_reg/remote_access_reg.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 9fd9defc-2768-11f1-9dd5-629be353806a
3+
date: '2026-03-24'
4+
description: Generated datasets for random dll extension in attack range.
5+
environment: attack_range
6+
directory: random_dll_extension
7+
mitre_technique:
8+
- T1218.011
9+
datasets:
10+
- name: random_dll_rundll32.log
11+
path: /datasets/attack_techniques/T1218.011/random_dll_extension/random_dll_rundll32.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:fcab984bb700abbd3fd27a150cbd70b907f608ea177c3487cb04796946f2e614
3+
size 8253

0 commit comments

Comments
 (0)