Skip to content

Commit

Permalink
adding intune dataset
Browse files Browse the repository at this point in the history
  • Loading branch information
dluxtron committed Jan 7, 2025
1 parent 5912f8e commit 04f6017
Show file tree
Hide file tree
Showing 2 changed files with 14 additions and 0 deletions.
3 changes: 3 additions & 0 deletions datasets/attack_techniques/T1072/intune/intune.log
Git LFS file not shown
11 changes: 11 additions & 0 deletions datasets/attack_techniques/T1072/intune/intune.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
author: Dean Luxton
id: 75a7e34c-73e2-4084-8c59-530cc763e941
date: '2025-01-07'
description: Performing the Death from Above attack moving laterally from Intune management console to an Intune managed device.
environment: Frothly Dev Azure Tenant
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1072/intune/intune.log
sourcetypes:
- azure:monitor:activity
references:
- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d

0 comments on commit 04f6017

Please sign in to comment.