diff --git a/datasets/attack_techniques/T1218.011/random_dll_extensions/random_dll_extensions.yml b/datasets/attack_techniques/T1218.011/random_dll_extensions/random_dll_extensions.yml new file mode 100644 index 00000000..f8b63b45 --- /dev/null +++ b/datasets/attack_techniques/T1218.011/random_dll_extensions/random_dll_extensions.yml @@ -0,0 +1,13 @@ +author: Teoderick Contreras, Splunk +id: 935146dc-29c7-11f1-a458-629be353806a +date: '2026-03-27' +description: Generated datasets for random dll extensions in attack range. +environment: attack_range +directory: rundll32_random_dll_extensions +mitre_technique: +- T1218.011 +datasets: +- name: rundll32_non_dll.log + path: /datasets/attack_techniques/T1218.011/random_dll_extensions/rundll32_non_dll.log + sourcetype: 'XmlWinEventLog' + source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' \ No newline at end of file diff --git a/datasets/attack_techniques/T1218.011/random_dll_extensions/rundll32_non_dll.log b/datasets/attack_techniques/T1218.011/random_dll_extensions/rundll32_non_dll.log new file mode 100644 index 00000000..4b2ce304 --- /dev/null +++ b/datasets/attack_techniques/T1218.011/random_dll_extensions/rundll32_non_dll.log @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b5668b9465719f4b748f7a943b1e3c3328d7b4710be98927c830a10fdc659024 +size 6063