Skip to content
Merged

lokibot #1031

Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Git LFS file not shown
13 changes: 13 additions & 0 deletions datasets/attack_techniques/T1071.004/vbc_dnsquery/vbc_dnsquery.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
author: Teoderick Contreras, Splunk
id: 489169c0-9ea7-11f0-ba06-629be353806a
date: '2025-10-01'
description: Generated datasets for vbc dnsquery in attack range.
environment: attack_range
directory: vbc_dnsquery
mitre_technique:
- T1071.004
datasets:
- name: vbc_dns_query.log
path: /datasets/attack_techniques/T1071.004/vbc_dnsquery/vbc_dns_query.log
sourcetype: 'XmlWinEventLog'
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
2 changes: 2 additions & 0 deletions datasets/m365_copilot/m365_copilot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@ id: 0bf90131-c582-4976-85b8-711d2c2c1926
date: '2025-09-25'
description: |
Logs from M365 Copilot Access Logs via Splunk Add-on for M365 and Exported Logs from eDsicovery Purview. Contains actual access logs and jailbreak attacks.
environment: attack_range
directory: m365_copilot
mitre_technique: []
datasets:
- name: m365_access_logs
Expand Down
Loading