File tree Expand file tree Collapse file tree 10 files changed +71
-60
lines changed
datasets/attack_techniques
T1030/osquery_data_chunking
T1037.002/osquery_logon_scripts
T1053.004/osquery_persistence
T1068/osquery_system_startup
T1070/osquery_log_removal
T1135/osquery_share_discovery
T1136/osquery_account_creation
T1555.001/osquery_keychains
T1564.001/osquery_hidden_files Expand file tree Collapse file tree 10 files changed +71
-60
lines changed Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: e1ad8f03-6cb5-4ae9-a0c0-b9eb9ff0e4b8
33date : ' 2026-02-19'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1030/osquery_data_chunking/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1030/
6+ mitre_technique :
7+ - T1030
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1030/osquery_data_chunking/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: 69fb68a6-dce5-400f-8a5e-086abda181aa
33date : ' 2026-02-19'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.002/osquery_logon_scripts/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1037/002/
6+ mitre_technique :
7+ - T1037.002
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1037.002/osquery_logon_scripts/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,11 @@ id: a319c571-0d12-4af7-b3dc-a30907e98277
33date : ' 2026-02-20'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.004/osquery_persistence/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1053/004/
6+ mitre_technique :
7+ - T1053.004
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1053.004/osquery_persistence/osquery.log
13+
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: bb5c9118-aec9-4d94-b3a5-cf5e7f422740
33date : ' 2026-02-20'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/osquery_system_startup/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1068/
6+ mitre_technique :
7+ - T1068
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1068/osquery_system_startup/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: 06297035-0abf-485a-9c4c-9f416999d845
33date : ' 2026-02-19'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/osquery_log_removal/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1070/
6+ mitre_technique :
7+ - T1070
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1070/osquery_log_removal/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: d93e309a-f7b1-4bef-b8b7-b447f1f616a3
33date : ' 2026-02-20'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/osquery_share_discovery/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1135/
6+ mitre_technique :
7+ - T1135
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1135/osquery_share_discovery/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: 06297035-0abf-485a-9c4c-9f416999d845
33date : ' 2026-02-19'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136/osquery_account_creation/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1136/
6+ mitre_technique :
7+ - T1136
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1136/osquery_account_creation/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: 324fc256-70c7-4e68-a32e-e2886f6245bb
33date : ' 2026-02-19'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543/osquery_ketxload/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1543
6+ mitre_technique :
7+ - T1543
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1543/osquery_ketxload/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: d9cbe409-3012-48d7-8926-b5ee0287ee3f
33date : ' 2026-02-19'
44description : Generation of Mac OSX techniques involving keychains and osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.001/osquery_keychains/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1555/001/
6+ mitre_technique :
7+ - T1555.001
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1555.001/osquery_keychains/osquery.log
Original file line number Diff line number Diff line change @@ -3,9 +3,10 @@ id: 649730e9-20c1-4776-b902-2c4fc819b00c
33date : ' 2026-02-19'
44description : Generation of Mac OSX techniques logged with osquery
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1564.001/osquery_hidden_files/osquery.log
8- sourcetypes :
9- - osquery:results
10- references :
11- - https://attack.mitre.org/techniques/T1564/001/
6+ mitre_technique :
7+ - T1564.001
8+ datasets :
9+ - name : osquery:results
10+ sourcetype : osquery:results
11+ source : osquery:results
12+ path : /datasets/attack_techniques/T1564.001/osquery_hidden_files/osquery.log
You can’t perform that action at this time.
0 commit comments