Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-01-10 17:05:29 -08:00
committed by GitHub
16 changed files with 637 additions and 0 deletions
@@ -0,0 +1,71 @@
name: Linux Add Files In Known Crontab Directories
id: 023f3452-5f27-11ec-bf00-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies a suspicious file creation in known
cron table directories. This event is commonly abuse by malware, adversaries and
red teamers to persist on the target or compromised host. crontab or cronjob is
like a schedule task in windows environment where you can create an executable or
script on the known crontab directories to run it base on its schedule. This Anomaly
query is a good indicator to look further what file is added and who added the file
if to consider it legitimate file.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/etc/cron*",
"*/var/spool/cron/*") by Filesystem.dest Filesystem.file_create_time Filesystem.file_name
Filesystem.process_guid Filesystem.file_path | `drop_dm_object_name(Filesystem)`
| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `linux_add_files_in_known_crontab_directories_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the file name, file path, and process_guid executions from your endpoints.
If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can create file in crontab
folders for automation purposes. Please update the filter macros to remove false positives.
references:
- https://www.sandflysecurity.com/blog/detecting-cronrat-malware-on-linux-instantly/
- https://www.cyberciti.biz/faq/how-do-i-add-jobs-to-cron-under-linux-or-unix-oses/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.003
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.dest
- Filesystem.file_create_time
- Filesystem.file_name
- Filesystem.process_guid
- Filesystem.file_path
security_domain: endpoint
impact: 50
confidence: 50
risk_score: 25
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
message: a file $file_name$ is created in $file_path$ on $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16
automated_detection_testing: passed
@@ -0,0 +1,71 @@
name: Linux At Allow Config File Creation
id: 977b3082-5f3d-11ec-b954-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies a suspicious file creation of /etc/at.allow
or /etc/at.deny. These 2 files are commonly abused by malware, adversaries or red
teamers to persist on the targeted or compromised host. These config files can restrict or allow
user to execute "at" application (another schedule task application in
linux). attacker can create a user or add the compromised username to that config
file to execute "at" to schedule it malicious code. This anomaly detection can be
a good indicator to investigate further the entry in created config file and who
created it to verify if it is a false positive.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/etc/at.allow",
"*/etc/at.deny") by Filesystem.dest Filesystem.file_create_time Filesystem.file_name
Filesystem.process_guid Filesystem.file_path | `drop_dm_object_name(Filesystem)`
| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `linux_at_allow_config_file_creation_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the file name, file path, and process_guid executions from your endpoints.
If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can create this file for
automation purposes. Please update the filter macros to remove false positives.
references:
- https://linuxize.com/post/at-command-in-linux/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.003
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.dest
- Filesystem.file_create_time
- Filesystem.file_name
- Filesystem.process_guid
- Filesystem.file_path
security_domain: endpoint
impact: 50
confidence: 50
risk_score: 25
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
message: A file $file_name$ is created in $file_path$ on $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16
automated_detection_testing: passed
@@ -0,0 +1,72 @@
name: Linux At Application Execution
id: bf0a378e-5f3c-11ec-a6de-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies a suspicious process creation of At
application. This process can be used by malware, adversaries and red teamers to
create persistence entry to the targeted or compromised host with their malicious
code. This anomaly detection can be a good indicator to investigate the event before
and after this process execution, when it was executed and what schedule task it
will execute.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes
where Processes.process_name = at OR Processes.parent_process_name = at by Processes.dest
Processes.user Processes.parent_process_name Processes.process_name Processes.process
Processes.process_id Processes.parent_process_id Processes.process_guid | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_at_application_execution_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can use this application
for automation purposes. Please update the filter macros to remove false positives.
references:
- https://attack.mitre.org/techniques/T1053/001/
- https://www.linkedin.com/pulse/getting-attacker-ip-address-from-malicious-linux-job-craig-rowland/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.001
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
impact: 30
confidence: 30
risk_score: 9
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
message: At application was executed in $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16
automated_detection_testing: passed
@@ -0,0 +1,71 @@
name: Linux Edit Cron Table Parameter
id: 0d370304-5f26-11ec-a4bb-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Hunting
datamodel:
- Endpoint
description: The following analytic identifies a suspicious cronjobs modification using crontab edit parameter.
This commandline parameter can be abuse by malware author, adversaries, and red
red teamers to add cronjob entry to their malicious code to execute to the schedule
they want. This event can also be executed by administrator or normal user for automation
purposes so filter is needed.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = crontab
Processes.process = "*crontab *" Processes.process = "* -e*" by Processes.dest Processes.user
Processes.parent_process_name Processes.process_name Processes.process Processes.process_id
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `linux_edit_cron_table_parameter_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can use this application
for automation purposes. Please update the filter macros to remove false positives.
references:
- https://attack.mitre.org/techniques/T1053/003/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/crontab_edit_parameter/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.003
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
impact: 30
confidence: 30
risk_score: 9
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
message: A possible crontab edit command $process$ executed on $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16
automated_detection_testing: passed
@@ -0,0 +1,72 @@
name: Linux Possible Append Command To At Allow Config File
id: 7bc20606-5f40-11ec-a586-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic looks for suspicious commandline that may use to append user entry to /etc/at.allow or /etc/at.deny.
These 2 files are commonly abused by malware, adversaries or red teamers to persist on the targeted or compromised host.
These config file can restrict user that can only execute at application (another schedule task application in linux). attacker can
create a user or add the compromised username to that config file to execute at to schedule it malicious code. This anomaly detection
can be a good indicator to investigate further the entry in created config file and who created it to verify if it is a false positive.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes
where Processes.process = "*echo*" AND Processes.process IN("*/etc/at.allow", "*/etc/at.deny")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_possible_append_command_to_at_allow_config_file_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives.
references:
- https://linuxize.com/post/at-command-in-linux/
- https://attack.mitre.org/techniques/T1053/001/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.001
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
impact: 30
confidence: 30
# (impact * confidence)/100
risk_score: 9
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
message: A commandline $process$ that may modify at allow config file in $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16
@@ -0,0 +1,71 @@
name: Linux Possible Append Cronjob Entry on Existing Cronjob File
id: b5b91200-5f27-11ec-bb4e-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Hunting
datamodel:
- Endpoint
description: This analytic looks for possible suspicious commandline that may use to append a code to any existing cronjob files
for persistence or privilege escalation. This technique is commonly abused by malware, adversaries and red teamers to automatically execute their code
within a existing or sometimes in normal cronjob script file.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes
where Processes.process = "*echo*" AND Processes.process IN("*/etc/cron*", "*/var/spool/cron/*", "*/etc/anacrontab*")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_possible_append_cronjob_entry_on_existing_cronjob_file_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives.
references:
- https://attack.mitre.org/techniques/T1053/003/
- https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability
- https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.003
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
impact: 70
confidence: 70
# (impact * confidence)/100
risk_score: 49
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
message: A commandline $process$ that may modify cronjob file in $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16
@@ -0,0 +1,71 @@
name: Linux Possible Cronjob Modification With Editor
id: dcc89bde-5f24-11ec-87ca-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Hunting
datamodel:
- Endpoint
description: This analytic looks for possible modification of cronjobs file using
editor. This event is can be seen in normal user but can also be a good hunting
indicator for unwanted user modifying cronjobs for possible persistence or privilege
escalation.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name IN("nano","vim.basic")
OR Processes.process IN ("*nano *", "*vi *", "*vim *")) AND Processes.process IN("*/etc/cron*",
"*/var/spool/cron/*", "*/etc/anacrontab*") by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `linux_possible_cronjob_modification_with_editor_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can use this commandline
for automation purposes. Please update the filter macros to remove false positives.
references:
- https://attack.mitre.org/techniques/T1053/003/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.003
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
impact: 20
confidence: 30
risk_score: 6
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
message: A commandline $process$ that may modify cronjob file using editor in $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16
automated_detection_testing: passed
+27
View File
@@ -0,0 +1,27 @@
name: Linux Persistence Techniques
id: e40d13e5-d38b-457e-af2a-e8e6a2f2b516
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
description: Monitor for activities and techniques associated with maintaining persistence
on a Linux system--a sign that an adversary may have compromised your environment.
narrative: Maintaining persistence is one of the first steps taken by attackers after
the initial compromise. Attackers leverage various custom and built-in tools to
ensure survivability and persistent access within a compromised enterprise. This
Analytic Story provides searches to help you identify various behaviors used by
attackers to maintain persistent access to a Linux environment.
references:
- https://attack.mitre.org/techniques/T1053/
- https://kifarunix.com/scheduling-tasks-using-at-command-in-linux/
- https://gtfobins.github.io/gtfobins/at/
- https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf
tags:
analytic_story: Linux Persistence Techniques
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
+27
View File
@@ -0,0 +1,27 @@
name: Linux Privilege Escalation
id: b9879c24-670a-44c0-895e-98cdb7d0e848
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
description: Monitor for and investigate activities that may be associated with a
Linux privilege-escalation attack, including unusual processes running on endpoints,
schedule task, services, setuid, root execution and more.
narrative: 'Privilege escalation is a "land-and-expand" technique, wherein an adversary
gains an initial foothold on a host and then exploits its weaknesses to increase
his privileges. The motivation is simple: certain actions on a Linux machine--such
as installing software--may require higher-level privileges than those the attacker
initially acquired. By increasing his privilege level, the attacker can gain the
control required to carry out his malicious ends. This Analytic Story provides searches
to detect and investigate behaviors that attackers may use to elevate their privileges
in your environment.'
references:
- https://attack.mitre.org/tactics/TA0004/
tags:
analytic_story: Linux Privilege Escalation
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -0,0 +1,12 @@
name: Linux Add Files In Known Crontab Directories Unit Test
tests:
- name: Linux Add Files In Known Crontab Directories
file: endpoint/linux_add_files_in_known_crontab_directories.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: sysmon_linux.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
@@ -0,0 +1,12 @@
name: Linux At Allow Config File Creation Unit Test
tests:
- name: Linux At Allow Config File Creation
file: endpoint/linux_at_allow_config_file_creation.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: sysmon_linux.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
@@ -0,0 +1,12 @@
name: Linux At Application Execution Unit Test
tests:
- name: Linux At Application Execution
file: endpoint/linux_at_application_execution.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: sysmon_linux.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
@@ -0,0 +1,12 @@
name: Linux Edit Cron Table Parameter Unit Test
tests:
- name: Linux Edit Cron Table Parameter
file: endpoint/linux_edit_cron_table_parameter.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: sysmon_linux.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/crontab_edit_parameter/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
@@ -0,0 +1,12 @@
name: Linux Possible Append Command To At Allow Config File Unit Test
tests:
- name: Linux Possible Append Command To At Allow Config File
file: endpoint/linux_possible_append_command_to_at_allow_config_file.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-30d'
latest_time: 'now'
attack_data:
- file_name: sysmon_linux.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
@@ -0,0 +1,12 @@
name: Linux Possible Append Cronjob Entry on Existing Cronjob File Unit Test
tests:
- name: Linux Possible Append Cronjob Entry on Existing Cronjob File
file: endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-30d'
latest_time: 'now'
attack_data:
- file_name: sysmon_linux.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
@@ -0,0 +1,12 @@
name: Linux Possible Cronjob Modification With Editor Unit Test
tests:
- name: Linux Possible Cronjob Modification With Editor
file: endpoint/linux_possible_cronjob_modification_with_editor.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: sysmon_linux.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux