We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 81b7ee2 commit f9504aeCopy full SHA for f9504ae
2 files changed
datasets/attack_techniques/T1059/vmtoolsd/vmtoolsd_execution.log
@@ -0,0 +1,3 @@
1
+version https://git-lfs.github.com/spec/v1
2
+oid sha256:cdb0794700ffe957bbf8914768c60f43eaf3261c7c2f8c1c06d7c01e60f6be25
3
+size 2385
datasets/attack_techniques/T1059/vmtoolsd/vmtoolsd_execution.yml
@@ -0,0 +1,11 @@
+author: Raven Tait, Splunk
+id: 45640c5f-9ef7-4d93-aa3e-2bc188d0be0a
+date: '2025-07-30'
4
+description: 'Sample of Sysmon events showing execution of commands on a host via VMWare Tools.'
5
+environment: custom
6
+dataset:
7
+- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/vmtoolsd_execution/vmtoolsd_execution.log
8
+sourcetypes:
9
+- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10
+references:
11
+- https://attack.mitre.org/techniques/T1059
0 commit comments