Skip to content

Commit b514264

Browse files
committed
Big dump of snapattack logs
1 parent 0ff7f1e commit b514264

File tree

226 files changed

+1883
-0
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

226 files changed

+1883
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:76c77dc261b4e0afc62ef81c33073eea8858b6626f946b1c7849af9d94b1c6dd
3+
size 1949
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Raven Tait, Splunk
2+
id: 359d5738-ce1c-40f4-8360-d544dab6db59
3+
date: '2026-04-01'
4+
description: Generated datasets for Windows String Manipulation Techniques in attack
5+
range.
6+
environment: attack_range
7+
directory: snapattack
8+
mitre_technique:
9+
- T1001
10+
datasets:
11+
- name: snapattack
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Security
14+
path: /datasets/attack_techniques/T1001/snapattack/snaattack.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:c22994ec5fa481609dfbb3403dc51d803cb1f0665d3aab29da8f5e8a9766f4af
3+
size 58587
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Raven Tait, Splunk
2+
id: 23bcd20e-abc1-43fa-bd6f-117cb360633e
3+
date: '2026-04-01'
4+
description: Generated datasets for Windows Evidence of LSASS Shtinkering - AppCrash
5+
Reports in attack range.
6+
environment: attack_range
7+
directory: snapattack
8+
mitre_technique:
9+
- T1003.001
10+
datasets:
11+
- name: snapattack
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
14+
path: /datasets/attack_techniques/T1003.001/snapattack/snaattack.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:f19d2035e279d3a5faaf7ac2a18f71d296f965cbe6389f8a905806ba50565b02
3+
size 7063
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Raven Tait, Splunk
2+
id: df5b874a-91f8-4eca-bf06-2570a6f7834b
3+
date: '2026-04-01'
4+
description: Generated datasets for Windows Usage of Mimikatz lsadump::sam module
5+
(PoSh) in attack range.
6+
environment: attack_range
7+
directory: snapattack
8+
mitre_technique:
9+
- T1003.002
10+
datasets:
11+
- name: snapattack
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
14+
path: /datasets/attack_techniques/T1003.002/snapattack/snaattack.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:50290b7f98c2059cb340a40c02fddc932a9815a1be32eef9074e839ae595ef4f
3+
size 7772
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Raven Tait, Splunk
2+
id: 53065f7f-c068-4a10-8009-26bb81ba80f9
3+
date: '2026-04-01'
4+
description: Generated datasets for Windows Explorer mounting a ntdsutil snapshot
5+
in attack range.
6+
environment: attack_range
7+
directory: snapattack
8+
mitre_technique:
9+
- T1003.003
10+
datasets:
11+
- name: snapattack
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
14+
path: /datasets/attack_techniques/T1003.003/snapattack/snaattack.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:4ba0ba771f144bd9f8847a0e9e40e21d15b7e966d19d64031e408611da6608f6
3+
size 4872
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Raven Tait, Splunk
2+
id: e30f8af0-68c6-4d63-93f7-c835dee26282
3+
date: '2026-04-01'
4+
description: Generated datasets for Windows Usage of Mimikatz lsadump::secrets module
5+
(Sysmon) in attack range.
6+
environment: attack_range
7+
directory: snapattack
8+
mitre_technique:
9+
- T1003.004
10+
datasets:
11+
- name: snapattack
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Security
14+
path: /datasets/attack_techniques/T1003.004/snapattack/snaattack.log

0 commit comments

Comments
 (0)