mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
de
This commit is contained in:
@@ -34,7 +34,7 @@ tags:
|
||||
- Suspicious DNS Traffic
|
||||
- Dynamic DNS
|
||||
- Command and Control
|
||||
- data exfiltration
|
||||
- Data Exfiltration
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log
|
||||
|
||||
@@ -32,7 +32,7 @@ tags:
|
||||
- Suspicious DNS Traffic
|
||||
- Dynamic DNS
|
||||
- Command and Control
|
||||
- data exfiltration
|
||||
- Data Exfiltration
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log
|
||||
|
||||
@@ -34,7 +34,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Command and Control
|
||||
- data exfiltration
|
||||
- Data Exfiltration
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/archive_http_post/stream_http_events.log
|
||||
|
||||
@@ -24,7 +24,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Command and Control
|
||||
- data exfiltration
|
||||
- Data Exfiltration
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/plain_exfil_data/stream_http_events.log
|
||||
|
||||
Reference in New Issue
Block a user