Skip to content

Commit

Permalink
adding azurehound and spn privesc datasets
Browse files Browse the repository at this point in the history
  • Loading branch information
dluxtron committed Jan 7, 2025
1 parent 04f6017 commit 612c290
Show file tree
Hide file tree
Showing 6 changed files with 46 additions and 0 deletions.
Git LFS file not shown
11 changes: 11 additions & 0 deletions datasets/attack_techniques/T1087.004/azurehound/azurehound.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
author: Dean Luxton
id: 14a1f8ea-e34a-449d-9081-0f16341e83c9
date: '2025-01-07'
description: Detonating AzureHound against Frothly
environment: Frothly Azure
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.004/azurehound/azurehound.log
sourcetypes:
- azure:monitor:aad
references:
- https://github.com/SpecterOps/AzureHound
Git LFS file not shown
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
author: Dean Luxton
id: db4f6922-ab94-4c29-aa66-ccbfcf86ce7b
date: '2025-01-07'
description: Performing SPN Priviliege escalation.
environment: Frothly Azure
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log
sourcetypes:
- azure:monitor:aad
references:
- https://github.com/mvelazc0/BadZure
- https://www.splunk.com/en_us/blog/security/hunting-m365-invaders-navigating-the-shadows-of-midnight-blizzard.html
- https://posts.specterops.io/microsoft-breach-what-happened-what-should-azure-admins-do-da2b7e674ebc
Git LFS file not shown
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
author: Dean Luxton
id: db4f6922-ab94-4c29-aa66-ccbfcf86ce7b
date: '2025-01-07'
description: Performing SPN Priviliege escalation.
environment: Frothly Azure
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log
sourcetypes:
- azure:monitor:aad
references:
- https://github.com/mvelazc0/BadZure
- https://www.splunk.com/en_us/blog/security/hunting-m365-invaders-navigating-the-shadows-of-midnight-blizzard.html
- https://posts.specterops.io/microsoft-breach-what-happened-what-should-azure-admins-do-da2b7e674ebc

0 comments on commit 612c290

Please sign in to comment.