Skip to content

Commit 3f178b7

Browse files
authored
Merge pull request #1099 from splunk/fix_cwd_path_detections
fix_cwd_path_detections
2 parents 5f19dcf + 6c11ee7 commit 3f178b7

File tree

12 files changed

+96
-0
lines changed

12 files changed

+96
-0
lines changed
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: ebb93346-cab0-11f0-9d54-629be353806a
3+
date: '2025-11-26'
4+
description: Generated datasets for auditd path cron in attack range.
5+
environment: attack_range
6+
directory: auditd_path_cron
7+
mitre_technique:
8+
- T1053.003
9+
datasets:
10+
- name: path_cron.log
11+
path: /datasets/attack_techniques/T1053.003/auditd_path_cron/path_cron.log
12+
sourcetype: 'auditd'
13+
source: 'auditd'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:d1781b8eef7b1b634222d6cbc00044798f5ccadd1130de8517059f39ccec57cc
3+
size 2790
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 30034558-caa9-11f0-9d54-629be353806a
3+
date: '2025-11-26'
4+
description: Generated datasets for auditd path ssh config in attack range.
5+
environment: attack_range
6+
directory: auditd_path_ssh_config
7+
mitre_technique:
8+
- T1098.004
9+
datasets:
10+
- name: path_ssh_config.log
11+
path: /datasets/attack_techniques/T1098.004/auditd_path_ssh_config/path_ssh_config.log
12+
sourcetype: 'auditd'
13+
source: 'auditd'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:221486c9e0f0e8101de8d8f2198586f3119bf6e6548de6804aa00da26e2ea8e4
3+
size 1441
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: f685a614-cab1-11f0-9d54-629be353806a
3+
date: '2025-11-26'
4+
description: Generated datasets for auditd path sysrq in attack range.
5+
environment: attack_range
6+
directory: auditd_path_sysrq
7+
mitre_technique:
8+
- T1529
9+
datasets:
10+
- name: path_sysrq.log
11+
path: /datasets/attack_techniques/T1529/auditd_path_sysrq/path_sysrq.log
12+
sourcetype: 'auditd'
13+
source: 'auditd'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:6c4ca9e6150c822cf1b12e8a1090e0f1007b084fb0f8ab0c330d289516f7d823
3+
size 523
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: af16a08e-caa8-11f0-9d54-629be353806a
3+
date: '2025-11-26'
4+
description: Generated datasets for auditd path cwd doas conf in attack range.
5+
environment: attack_range
6+
directory: auditd_path_cwd_doas_conf
7+
mitre_technique:
8+
- T1548.003
9+
datasets:
10+
- name: path_doas.log
11+
path: /datasets/attack_techniques/T1548.003/auditd_path_cwd_doas_conf/path_doas.log
12+
sourcetype: 'auditd'
13+
source: 'auditd'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:42b3a666077a4b1f6335788d5cc3d358b6a9e83c8cf2ef3f309f9727bed6fa0a
3+
size 1206
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Teoderick Contreras, Splunk
2+
id: 982cabce-caa9-11f0-9d54-629be353806a
3+
date: '2025-11-26'
4+
description: Generated datasets for auditd path sudoers in attack range.
5+
environment: attack_range
6+
directory: auditd_path_sudoers
7+
mitre_technique:
8+
- T1548.003
9+
datasets:
10+
- name: path_sudoers.log
11+
path: /datasets/attack_techniques/T1548.003/auditd_path_sudoers/path_sudoers.log
12+
sourcetype: 'auditd'
13+
source: 'auditd'
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:31daf0628fc00efcb59f410b9376b6f9220d12eac5137bd58eee91a97b2c22cc
3+
size 765

0 commit comments

Comments
 (0)