Skip to content

Commit 836bb3d

Browse files
authored
Merge pull request #1158 from splunk/snap_conversion
Snap conversion
2 parents 286db79 + 9ddcc35 commit 836bb3d

46 files changed

Lines changed: 265 additions & 0 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Raven Tait, Splunk
2+
id: 552e13f8-267f-4a91-a56f-9209ab4e2f1f
3+
date: '2026-04-20'
4+
description: Generated datasets for Linux Evidence of BPFdoor implant - creation of
5+
known lockfiles in attack range.
6+
environment: attack_range
7+
directory: snapattack
8+
mitre_technique:
9+
- T1014
10+
datasets:
11+
- name: snapattack
12+
sourcetype: sysmon:linux
13+
source: Syslog:Linux-Sysmon/Operational
14+
path: /datasets/attack_techniques/T1014/snapattack/snapattack_linux.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:d4e26a8daf0571d3cf218dc3157161414faac7dac641a12354b3df35bff42cf1
3+
size 950

datasets/attack_techniques/T1021.004/snapattack/snapattack.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,3 +11,7 @@ datasets:
1111
sourcetype: XmlWinEventLog
1212
source: XmlWinEventLog:Security
1313
path: /datasets/attack_techniques/T1021.004/snapattack/snaattack.log
14+
- name: snapattack_linux
15+
sourcetype: sysmon:linux
16+
source: Syslog:Linux-Sysmon/Operational
17+
path: /datasets/attack_techniques/T1021.004/snapattack/snapattack_linux.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:a12e30866bb511ec6d3817f616bc3cd1dc33b2efc291b7b035da4275c8c29eba
3+
size 1675

datasets/attack_techniques/T1033/snapattack/snapattack.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,3 +11,7 @@ datasets:
1111
sourcetype: XmlWinEventLog
1212
source: XmlWinEventLog:Security
1313
path: /datasets/attack_techniques/T1033/snapattack/snaattack.log
14+
- name: snapattack_linux
15+
sourcetype: sysmon:linux
16+
source: Syslog:Linux-Sysmon/Operational
17+
path: /datasets/attack_techniques/T1033/snapattack/snapattack_linux.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:aab118f8742cc2fb7895dd531034e5ac436081ebba31d30f5f654d98ff68b2e1
3+
size 9007
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Raven Tait, Splunk
2+
id: bf223b24-4cb9-44aa-b43d-63c5d564355a
3+
date: '2026-04-20'
4+
description: Generated datasets for Linux GobRAT Malware Execution in attack range.
5+
environment: attack_range
6+
directory: snapattack
7+
mitre_technique:
8+
- T1036.004
9+
datasets:
10+
- name: snapattack
11+
sourcetype: sysmon:linux
12+
source: Syslog:Linux-Sysmon/Operational
13+
path: /datasets/attack_techniques/T1036.004/snapattack/snapattack_linux.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:01df66c08bbff373951b6bce7d80390d6294f1672e7e70e8aa92f12aa3e68fc4
3+
size 1553

datasets/attack_techniques/T1036/snapattack/snapattack.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,3 +12,7 @@ datasets:
1212
sourcetype: XmlWinEventLog
1313
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1414
path: /datasets/attack_techniques/T1036/snapattack/snaattack.log
15+
- name: snapattack_linux
16+
sourcetype: sysmon:linux
17+
source: Syslog:Linux-Sysmon/Operational
18+
path: /datasets/attack_techniques/T1036/snapattack/snapattack_linux.log
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:15b880706f6e080fd652fd6fc47bd8d458859b001eca77ef86d6191a3420409c
3+
size 2837

0 commit comments

Comments
 (0)