Skip to content

Commit 1d03704

Browse files
authored
Merge pull request #1036 from splunk/fsutil
add fsutil symlinkevaluation dataset
2 parents 710d2a3 + a5010cc commit 1d03704

File tree

3 files changed

+17
-0
lines changed

3 files changed

+17
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:055f282a2c4f1396db511c10ed4016241072fcbfb78e8de64f6614601c554109
3+
size 1949
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: 169da367-87f4-413d-b0c9-b8c13e01d489
3+
date: '2025-10-07'
4+
description: Generated datasets for fsutil SymlinkEvaluation set in attack range.
5+
environment: attack_range
6+
directory: fsutil_symlink_eval
7+
mitre_technique:
8+
- T1222.001
9+
datasets:
10+
- name: fsutil_symlink_eval.log
11+
path: /datasets/attack_techniques/T1222.001/fsutil_symlink_eval/fsutil_symlink_eval.log
12+
sourcetype: XmlWinEventLog
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'

datasets/ollama/ollama_server_data.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ id: 9d1f6bd1-754a-481c-ad54-5a837f86d12b
33
date: '2025-10-05'
44
description: Logs from Ollama server, contain errors, system messages, http calls, methods and endpoint uris.
55
mitre_technique: []
6+
environment: attack_range
67
datasets:
78
- name: ollama_server_data
89
path: /datasets/ollama/server.log

0 commit comments

Comments
 (0)