Skip to content

Commit 0311f81

Browse files
authored
Merge pull request #1044 from splunk/new-dataset-oct25
add new datasets for ip scanner, pstools and defender
2 parents 9268150 + 28462be commit 0311f81

File tree

6 files changed

+48
-0
lines changed

6 files changed

+48
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:3a4fb67d7aa2e86c0ecedb60c9d02c9b4a178a7a8fdf228c0535a965ce7dad6c
3+
size 59641
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: a846253e-7b37-4713-8a78-da3c058658cc
3+
date: '2025-10-13'
4+
description: Generated datasets covering the execution of Advanced IP / Port Scanner in attack range.
5+
environment: attack_range
6+
directory: advanced_ip_port_scanner
7+
mitre_technique:
8+
- T1046
9+
datasets:
10+
- name: advanced_ip_port_scanner.log
11+
path: /datasets/attack_techniques/T1046/advanced_ip_port_scanner/advanced_ip_port_scanner.log
12+
sourcetype: XmlWinEventLog
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:ceeb24d90b3d08428440a0c50427e12c5fea1d15a6172e5bed25eda46384cd29
3+
size 35818
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: cb4024aa-8397-4739-adeb-7e2e2e14ef30
3+
date: '2025-10-15'
4+
description: Generated datasets covering the execution of different tools of the PsTools Sysinternals suit in attack range.
5+
environment: attack_range
6+
directory: sysinternals_pstools
7+
mitre_technique:
8+
- T1046
9+
datasets:
10+
- name: sysinternals_pstools.log
11+
path: /datasets/attack_techniques/T1082/sysinternals_pstools/sysinternals_pstools.log
12+
sourcetype: XmlWinEventLog
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:ba24768e57d593f7fb188ddbd9612a54709e72562d084f60f50359497ba04ab3
3+
size 10743
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: 179da367-87f4-413d-b0c9-b8c13e01d489
3+
date: '2025-10-13'
4+
description: Generated datasets for disabling or allowing certain ASR rule or threat IDs respectively in attack range.
5+
environment: attack_range
6+
directory: disable_defender_asr_or_threats
7+
mitre_technique:
8+
- T1562.001
9+
datasets:
10+
- name: disable_defender_asr_or_threats.log
11+
path: /datasets/attack_techniques/T1562.001/disable_defender_asr_or_threats/disable_defender_asr_or_threats.log
12+
sourcetype: XmlWinEventLog
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'

0 commit comments

Comments
 (0)