Skip to content

Commit 387a52c

Browse files
committed
Add dataset for T1546.015 BitLocker COM Hijacking lateral movement
1 parent 5f19dcf commit 387a52c

File tree

4 files changed

+30
-0
lines changed

4 files changed

+30
-0
lines changed
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
*.log filter=lfs diff=lfs merge=lfs -text
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
name: BitLocker COM Hijacking Lateral Movement
3+
id: b8f4c2a1-9e7d-4f3b-8a1c-5d9e7f2b6a3e
4+
version: 1
5+
date: '2025-11-25'
6+
author: Ali Atashgar (AAtashGar)
7+
type: dataset
8+
description: Simulated Windows Security and System events demonstrating the
9+
BitLocker Network Unlock COM Object Hijacking lateral movement technique
10+
(T1574.015 / T1546.015) using RemoteRegistry service enablement, HKCU CLSID
11+
manipulation, and execution via baaupdate.exe or BdeUISrv.exe.
12+
references:
13+
- https://ipurple.team/2025/08/04/lateral-movement-bitlocker/
14+
- https://github.com/rtecCyberSec/BitlockMove
15+
attack_data:
16+
- file_name: windows-security.log
17+
data: datasets/attack_techniques/T1546.015/bitlocker_com_hijacking/windows-security.log
18+
source: WinEventLog:Security
19+
sourcetype: WinEventLog:Security
20+
- file_name: windows-system.log
21+
data: datasets/attack_techniques/T1546.015/bitlocker_com_hijacking/windows-system.log
22+
source: WinEventLog:System
23+
sourcetype: WinEventLog:System
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:8a9cf4b18a6383c2baefec1bfab29f561bb3055d2dba9df3062f3f97a81def33
3+
size 7003
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:52199fd95101d48968b9683959cd06e894d23f036480253c13862589222c182f
3+
size 1058

0 commit comments

Comments
 (0)