diff --git a/datasets/suspicious_behaviour/network_traffic_from_inactive_accounts/network_traffic_from_inactive_accounts.yaml b/datasets/suspicious_behaviour/network_traffic_from_inactive_accounts/network_traffic_from_inactive_accounts.yaml new file mode 100644 index 00000000..2ce45de5 --- /dev/null +++ b/datasets/suspicious_behaviour/network_traffic_from_inactive_accounts/network_traffic_from_inactive_accounts.yaml @@ -0,0 +1,17 @@ +{ + "author": "Zaki Zarkasih Al Mustafa", + "id": "e08aa2f6-7d90-4ab8-af11-da4df38bb7ff", + "date": "2024-10-28", + "description": "This dataset is synthetically generated for testing detections related to inactive account activity based on network logs.", + "environment": "attack_range", + "dataset": [ + "https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/network_traffic/inactive_account_activity_detection/network_traffic_inactive_account_activity.json" + ], + "sourcetypes": [ + "net_traffic" + ], + "references": [ + "https://attack.mitre.org/techniques/T1078/004/", + "https://attack.mitre.org/techniques/T1535/" + ] +} diff --git a/datasets/suspicious_behaviour/network_traffic_from_inactive_accounts/network_traffic_inactive_account_activity.json b/datasets/suspicious_behaviour/network_traffic_from_inactive_accounts/network_traffic_inactive_account_activity.json new file mode 100644 index 00000000..13fcd9db --- /dev/null +++ b/datasets/suspicious_behaviour/network_traffic_from_inactive_accounts/network_traffic_inactive_account_activity.json @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fe5cd9fcd4e4ad2102380e8851174f6aaae3d0147b54f8b6d2bde6fc03fbe68b +size 8084