Skip to content

Commit c41f736

Browse files
authored
Merge pull request #1067 from splunk/wsus-sa
More WSUS data
2 parents 7f97eec + a599560 commit c41f736

File tree

4 files changed

+22
-1
lines changed

4 files changed

+22
-1
lines changed

datasets/attack_techniques/T1505.003/T1505.003.yml

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
author: Michael Haag
22
id: cc9b2609-efc9-11eb-926b-550bf0943fbb
3-
date: '2025-10-24'
3+
date: '2025-10-28'
44
description: The following data was produced to emulate IIS, w3wp.exe, spawning shells,
55
simulating web shell activity. In addition, behavior related to Microsoft Exchange
66
Server's Unified Messaging services, umworkerprocess.exe and umservice.exe, spawning
@@ -32,3 +32,15 @@ datasets:
3232
path: /datasets/attack_techniques/T1505.003/wsus-windows-sysmon.log
3333
sourcetype: XmlWinEventLog
3434
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
35+
- name: wsus-sa-windows-sysmon
36+
path: /datasets/attack_techniques/T1505.003/wsus-sa-windows-sysmon.log
37+
sourcetype: XmlWinEventLog
38+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
39+
- name: wsus-iis
40+
path: /datasets/attack_techniques/T1505.003/wsus-iis.log
41+
sourcetype: iis
42+
source: iis
43+
- name: wsus-suricata
44+
path: /datasets/attack_techniques/T1505.003/wsus-suricata.log
45+
sourcetype: suricata
46+
source: suricata
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:e5a3b0efb827df055104d0ddfa7660b8699a9713db37f27338a474838b19ed27
3+
size 18198
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:fd395beee7b6a091bf557930ee9b69103601ba0b7a04c6a27f82131402d88712
3+
size 20559
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:3fb605825f6598cbcde1f339cc2f9eebafee494525d133377733f16791d04aa0
3+
size 5499

0 commit comments

Comments
 (0)