Skip to content

Commit

Permalink
Merge pull request #3179 from splunk/only_sysmon
Browse files Browse the repository at this point in the history
Only for sysmon sources
  • Loading branch information
patel-bhavin authored Oct 31, 2024
2 parents e858298 + d079ce5 commit bbb418b
Show file tree
Hide file tree
Showing 699 changed files with 702 additions and 706 deletions.
2 changes: 1 addition & 1 deletion detections/endpoint/7zip_commandline_to_smb_share_path.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,4 +55,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon_7z.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -62,4 +62,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/account_discovery_with_net_app.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,4 +74,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/active_setup_registry_autostart.yml
Original file line number Diff line number Diff line change
Expand Up @@ -65,4 +65,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -57,4 +57,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -75,4 +75,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_sysmon/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -69,4 +69,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -65,4 +65,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -67,4 +67,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/allow_operation_with_consent_admin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -64,4 +64,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/anomalous_usage_of_7zip.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,4 +79,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/any_powershell_downloadfile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -86,4 +86,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/any_powershell_downloadstring.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,4 +87,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/attacker_tools_on_endpoint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,4 +68,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -72,4 +72,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.004/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/attempt_to_stop_security_service.yml
Original file line number Diff line number Diff line change
Expand Up @@ -81,4 +81,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
Expand Down
2 changes: 1 addition & 1 deletion detections/endpoint/auto_admin_logon_registry_entry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,4 +58,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/batch_file_write_to_system32.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,4 +68,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -61,4 +61,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -69,5 +69,5 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
update_timestamp: true
2 changes: 1 addition & 1 deletion detections/endpoint/bits_job_persistence.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log
Expand Down
2 changes: 1 addition & 1 deletion detections/endpoint/bitsadmin_download_file.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -82,4 +82,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -79,4 +79,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -76,4 +76,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/certutil_exe_certificate_extraction/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/certutil_with_decode_argument.yml
Original file line number Diff line number Diff line change
Expand Up @@ -84,4 +84,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/change_default_file_association.yml
Original file line number Diff line number Diff line change
Expand Up @@ -65,4 +65,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -61,4 +61,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/chcp_command_execution.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,4 +66,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/check_elevated_cmd_using_whoami.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,4 +61,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -76,4 +76,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/clop_common_exec_parameter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,4 +75,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -79,4 +79,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/cmd_carry_str_param/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/cmd_echo_pipe___escalation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -80,4 +80,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -84,4 +84,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,4 +60,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/darkside_cmstp_com/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/cobalt_strike_named_pipes.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,4 +71,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/common_ransomware_extensions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,4 +54,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/ransom-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/common_ransomware_notes.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,4 +57,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -59,4 +59,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/screenconnect/sysmon_app_extensions.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/conti_common_exec_parameter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,4 +74,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/inf1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -81,4 +81,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -79,4 +79,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.005/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -62,4 +62,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/create_remote_thread_into_lsass.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,4 +62,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -58,4 +58,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/creation_of_shadow_copy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/crowdstrike_falcon.log
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -70,4 +70,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -67,4 +67,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -67,4 +67,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/csc_net_on_the_fly_compilation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,4 +52,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/deleting_of_net_users.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,4 +76,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
2 changes: 1 addition & 1 deletion detections/endpoint/deleting_shadow_copies.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,4 +83,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Original file line number Diff line number Diff line change
Expand Up @@ -83,4 +83,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Loading

0 comments on commit bbb418b

Please sign in to comment.