-
Notifications
You must be signed in to change notification settings - Fork 125
Add dataset for T1546.015 BitLocker COM Hijacking lateral movement #1098
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
datasets/attack_techniques/T1546.015/bitlocker_com_hijacking/bitlocker_com_hijacking.yml
Outdated
Show resolved
Hide resolved
datasets/attack_techniques/T1546.015/bitlocker_com_hijacking/bitlocker_com_hijacking.yml
Outdated
Show resolved
Hide resolved
datasets/attack_techniques/T1546.015/bitlocker_com_hijacking/bitlocker_com_hijacking.yml
Outdated
Show resolved
Hide resolved
590d288 to
bf2d87e
Compare
|
Dear @nasbench, I quickly implemented the changes you suggested, the datasets are now xml and I also updated the yml file. |
Updated the BitLocker COM Hijacking dataset YAML file to streamline the structure and remove redundant entries.
|
@AAtashGar stop using AI to fix things. As this will lead to closing this PR :) Just do an export raw from Splunk without additional formatting |
|
Dear @nasbench, |

Adds simulated attack data for the novel BitLocker COM Hijacking technique (first public detection).
Related security_content PR: splunk/security_content#3801