Skip to content

Commit 194a902

Browse files
authored
Merge pull request #1088 from splunk/netsupport
netsupport
2 parents 27d52de + 98f9922 commit 194a902

File tree

6 files changed

+48
-0
lines changed

6 files changed

+48
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 0f2d6b50-c15e-11f0-8cf9-629be353806a
3+
date: '2025-11-14'
4+
description: Generated datasets for masquerading executable as non exec file type in attack range.
5+
environment: attack_range
6+
directory: masquerading_executable_as_non_exec_file_type
7+
mitre_technique:
8+
- T1036.008
9+
datasets:
10+
- name: non_exec_ext_but_exec_detected.log
11+
path: /datasets/attack_techniques/T1036.008/masquerading_executable_as_non_exec_file_type/non_exec_ext_but_exec_detected.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:eca1f193a3e5a521550ee6def74a333423ecba0e0666632971d64c7e6fb25ceb
3+
size 11937
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:8dfcc5222a610c12eebbbd305ef33779f6e454b3e5c7d4ed30f078b1389ff9bc
3+
size 7793
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: ddd747f6-c15d-11f0-8cf9-629be353806a
3+
date: '2025-11-14'
4+
description: Generated datasets for netsupport modules in attack range.
5+
environment: attack_range
6+
directory: netsupport_modules
7+
mitre_technique:
8+
- T1036
9+
datasets:
10+
- name: net_support_module.log
11+
path: /datasets/attack_techniques/T1036/netsupport_modules/net_support_module.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 24e060c4-c15e-11f0-8cf9-629be353806a
3+
date: '2025-11-14'
4+
description: Generated datasets for delete runmru reg in attack range.
5+
environment: attack_range
6+
directory: delete_runmru_reg
7+
mitre_technique:
8+
- T1112
9+
datasets:
10+
- name: runmru_deletion.log
11+
path: /datasets/attack_techniques/T1112/delete_runmru_reg/runmru_deletion.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:32fb866c1e62fd57d01a78ecb6a2114f8327e6bfcbc06d132e980e046efe6e4d
3+
size 13237

0 commit comments

Comments
 (0)