Skip to content

Commit 284dcf0

Browse files
authored
sysmon data for outlook writing zip (#1121)
* adding data * udpating
1 parent e39ddbc commit 284dcf0

File tree

2 files changed

+16
-0
lines changed

2 files changed

+16
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:81594d6183d8f23a3faa034057cb009f39c94393ac902bbc7bb9c9a459b45bd3
3+
size 7073
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Bhavin Patel, Splunk
2+
id: 822a7bed-b71f-4818-9f60-d1799a23528c
3+
date: '2026-01-23'
4+
description: This data is collected from an industary event that shows the execution of outlook.exe writing a zip file to the disk.
5+
environment: attack_range
6+
directory: outlook_writing_zip
7+
mitre_technique:
8+
- T1566.001
9+
datasets:
10+
- name: outlook_writing_zip
11+
path: /datasets/attack_techniques/T1566.001/outlook_writing_zip/outlook_writing_zip.log
12+
sourcetype: XmlWinEventLog
13+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

0 commit comments

Comments
 (0)