attack_data
attack_data copied to clipboard
A repository of curated datasets from various attacks
eg datasets/suspicious_behaviour/crowdstrike_stream/admin_weak_password_policy/admin_weak_password_policy.yml is marked with sourcetypes: - 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' should be crowdstrike:identities there are others besides this example. all the ones I found so far are in the crowdstrike stream folder,...
create as-rep roasting log data for detection rule
fix formatting issues that causes "no valid data found" error