diff --git a/datasets/attack_techniques/T1021.001/susp_default_rdp_creation/default_rdp.log b/datasets/attack_techniques/T1021.001/susp_default_rdp_creation/default_rdp.log new file mode 100644 index 00000000..01524116 --- /dev/null +++ b/datasets/attack_techniques/T1021.001/susp_default_rdp_creation/default_rdp.log @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:8167e56244359d728cb02384cf6a1d4fd25ef4312711fb29b17cca49c7606341 +size 2006 diff --git a/datasets/attack_techniques/T1021.001/susp_default_rdp_creation/susp_default_rdp_creation.yml b/datasets/attack_techniques/T1021.001/susp_default_rdp_creation/susp_default_rdp_creation.yml new file mode 100644 index 00000000..edfb172b --- /dev/null +++ b/datasets/attack_techniques/T1021.001/susp_default_rdp_creation/susp_default_rdp_creation.yml @@ -0,0 +1,13 @@ +author: Teoderick Contreras, Splunk +id: 8c89fa4a-b31d-11f0-894e-629be3538069 +date: '2025-10-27' +description: Generated datasets for susp default rdp creation in attack range. +environment: attack_range +directory: susp_default_rdp_creation +mitre_technique: +- T1021.001 +datasets: +- name: default_rdp.log + path: /datasets/attack_techniques/T1021.001/susp_default_rdp_creation/default_rdp.log + sourcetype: 'XmlWinEventLog' + source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' \ No newline at end of file