From 673a1f83032fb3361b7edc9064169b6cdfdc824b Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Fri, 7 Feb 2025 13:45:41 -0500 Subject: [PATCH] Upload --- .../windows-xml.log | 3 +++ .../windows-xml.yml | 14 ++++++++++++++ 2 files changed, 17 insertions(+) create mode 100644 datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.log create mode 100644 datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.yml diff --git a/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.log b/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.log new file mode 100644 index 00000000..edfcf154 --- /dev/null +++ b/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.log @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:4af0e2d1b8dfae2e6e7cd18dcb85db50a028effc8d46f9fe3cfc21b633b2e6c0 +size 3373 diff --git a/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.yml b/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.yml new file mode 100644 index 00000000..76b5d5d0 --- /dev/null +++ b/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.yml @@ -0,0 +1,14 @@ +author: Steven Dick +id: ea908665-bc39-4493-a20a-041543ba4f3b +date: '2025-01-28' +description: 'A sample event with a known malicous Task Name.' +environment: attack_range +dataset: +- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_with_suspect_name/windows-xml.log +sourcetypes: +- XmlWinEventLog +references: +- https://attack.mitre.org/techniques/T1053/005/ +- https://www.ic3.gov/CSA/2023/231213.pdf +- https://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/ +- https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_windows_tasks_list.csv \ No newline at end of file