Skip to content

Commit c3f03d1

Browse files
authored
Merge pull request #1135 from splunk/mac_data
Mac data
2 parents de713ff + eb0085c commit c3f03d1

File tree

20 files changed

+151
-0
lines changed

20 files changed

+151
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:cc3fda3ff1a0f3862b5cb17e82390a43f6fc54a5a4a9a118f019461727ecb2e8
3+
size 9992
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Raven Tait
2+
id: e1ad8f03-6cb5-4ae9-a0c0-b9eb9ff0e4b8
3+
date: '2026-02-19'
4+
description: Generation of Mac OSX techniques logged with osquery
5+
environment: attack_range
6+
mitre_technique:
7+
- T1030
8+
datasets:
9+
- name: osquery:results
10+
sourcetype: osquery:results
11+
source: osquery:results
12+
path: /datasets/attack_techniques/T1030/osquery_data_chunking/osquery.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:b9b92d8af052ca04218b44efc58915627fce032fb1a6fee5751c4bb6a33bd760
3+
size 17994
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Raven Tait
2+
id: 69fb68a6-dce5-400f-8a5e-086abda181aa
3+
date: '2026-02-19'
4+
description: Generation of Mac OSX techniques logged with osquery
5+
environment: attack_range
6+
mitre_technique:
7+
- T1037.002
8+
datasets:
9+
- name: osquery:results
10+
sourcetype: osquery:results
11+
source: osquery:results
12+
path: /datasets/attack_techniques/T1037.002/osquery_logon_scripts/osquery.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:6c25818a60216c479d081963996b39470a2799a6991fcd86b5479d7425cc3235
3+
size 5012
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Raven Tait
2+
id: a319c571-0d12-4af7-b3dc-a30907e98277
3+
date: '2026-02-20'
4+
description: Generation of Mac OSX techniques logged with osquery
5+
environment: attack_range
6+
mitre_technique:
7+
- T1053.004
8+
datasets:
9+
- name: osquery:results
10+
sourcetype: osquery:results
11+
source: osquery:results
12+
path: /datasets/attack_techniques/T1053.004/osquery_persistence/osquery.log
13+
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:3137c31603d3075c97373f932fbdd6ead2dc00f75b615a27857c2d52866d2686
3+
size 3314
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Raven Tait
2+
id: bb5c9118-aec9-4d94-b3a5-cf5e7f422740
3+
date: '2026-02-20'
4+
description: Generation of Mac OSX techniques logged with osquery
5+
environment: attack_range
6+
mitre_technique:
7+
- T1068
8+
datasets:
9+
- name: osquery:results
10+
sourcetype: osquery:results
11+
source: osquery:results
12+
path: /datasets/attack_techniques/T1068/osquery_system_startup/osquery.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:ce87d38d0b1aacefc671e5a097a8972ff414cd6f82f02b9b08968bd7b618a364
3+
size 5125
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Raven Tait
2+
id: 06297035-0abf-485a-9c4c-9f416999d845
3+
date: '2026-02-19'
4+
description: Generation of Mac OSX techniques logged with osquery
5+
environment: attack_range
6+
mitre_technique:
7+
- T1070
8+
datasets:
9+
- name: osquery:results
10+
sourcetype: osquery:results
11+
source: osquery:results
12+
path: /datasets/attack_techniques/T1070/osquery_log_removal/osquery.log

0 commit comments

Comments
 (0)