Skip to content

Commit 79a8395

Browse files
authored
Merge pull request #1089 from splunk/kerberos_coercion
Data for kerberos coercion with DNS
2 parents 23a0f45 + 0a89649 commit 79a8395

File tree

4 files changed

+30
-0
lines changed

4 files changed

+30
-0
lines changed
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
author: Raven Tait, Splunk
2+
id: 6f05e912-8743-4328-8ac2-4b0592918dfd
3+
date: '2025-11-14'
4+
description: Generated datasets for kerberos coercion using DNS in attack range.
5+
environment: attack_range
6+
directory: kerberos_coercion
7+
mitre_technique:
8+
- T1071.004
9+
datasets:
10+
- name: sysmon.log
11+
path: /datasets/attack_techniques/T1071.004/kerberos_coercion/sysmon.log
12+
sourcetype: 'XmlWinEventLog'
13+
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
14+
- name: suricata.log
15+
path: /datasets/attack_techniques/T1071.004/kerberos_coercion/suricata.log
16+
sourcetype: suricata
17+
source: suricata
18+
- name: windows-xml.log
19+
path: /datasets/attack_techniques/T1071.004/kerberos_coercion/windows-xml.log
20+
sourcetype: XmlWinEventLog
21+
source: XmlWinEventLog:Security
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:3455bfef4c69cff0466882787edce1d8f508fd58ca4d411ffc2a80f17981ca86
3+
size 2028
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:a2a1993d49ed6dc9be332d000d82a2162658315bcdce3eaedb59f180ad13538a
3+
size 3344
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:8838137aa5d4befb877163f1aeb28035792fe8a73674787cea4b9251739da74e
3+
size 14751

0 commit comments

Comments
 (0)