diff --git a/datasets/attack_techniques/T1027/url_encoded_curl/linux-sysmon.log b/datasets/attack_techniques/T1027/url_encoded_curl/linux-sysmon.log new file mode 100644 index 00000000..38fb273c --- /dev/null +++ b/datasets/attack_techniques/T1027/url_encoded_curl/linux-sysmon.log @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:17e68325c4a924d85169fe4a1754c9d74f51a0b4f5f51fb754c02b37d620c961 +size 1755 diff --git a/datasets/attack_techniques/T1027/url_encoded_curl/url_encoded_curl.yml b/datasets/attack_techniques/T1027/url_encoded_curl/url_encoded_curl.yml new file mode 100644 index 00000000..b4fd3f00 --- /dev/null +++ b/datasets/attack_techniques/T1027/url_encoded_curl/url_encoded_curl.yml @@ -0,0 +1,17 @@ +author: Nasreddine Bencherchali, Splunk +id: d9db07a0-13da-4fc5-8abe-451188ce3aa1 +date: '2026-02-02' +description: Generated dataset for URL encoded curl commands used in obfuscation techniques. +environment: attack_range +directory: url_encoded_curl +mitre_technique: +- T1027 +datasets: +- name: linux-sysmon + path: /datasets/attack_techniques/T1027/url_encoded_curl/linux-sysmon.log + sourcetype: sysmon:linux + source: Syslog:Linux-Sysmon/Operational +- name: windows-sysmon + path: /datasets/attack_techniques/T1027/url_encoded_curl/windows-sysmon.log + sourcetype: XmlWinEventLog + source: XmlWinEventLog:Windows-Sysmon/Operational diff --git a/datasets/attack_techniques/T1027/url_encoded_curl/windows-sysmon.log b/datasets/attack_techniques/T1027/url_encoded_curl/windows-sysmon.log new file mode 100644 index 00000000..14d80f89 --- /dev/null +++ b/datasets/attack_techniques/T1027/url_encoded_curl/windows-sysmon.log @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:e5ff5e20583627513c6fb99a5763e913fe5c6b6cbc983c13b0c236090968d26c +size 6249