Skip to content

added data source for new technique of attack - #1019

Merged
patel-bhavin merged 4 commits into
splunk:masterfrom
CheraghiMilad:attack_data_forlinux_auditd_sysrq
Sep 3, 2025
Merged

added data source for new technique of attack#1019
patel-bhavin merged 4 commits into
splunk:masterfrom
CheraghiMilad:attack_data_forlinux_auditd_sysrq

Conversation

@CheraghiMilad

Copy link
Copy Markdown
Contributor

I am writing a detection rule for a specific attack technique in Splunk, and I need to include my data source here. The technique name is linux_auditd_magic_system_request_key

Comment thread datasets/attack_techniques/T1529/linux_sysrq_abuse/linux_sysrq_abuse.log Outdated
@patel-bhavin

Copy link
Copy Markdown
Collaborator

When the data is uploaded correctly, Github will show you that :
image

@CheraghiMilad

Copy link
Copy Markdown
Contributor Author

@patel-bhavin Thanks for guiding me.

@patel-bhavin

patel-bhavin commented Aug 29, 2025

Copy link
Copy Markdown
Collaborator

@CheraghiMilad : great! PR is looking good,. we will merge this so that we can run unit-testing in the security content repo

For now please ignore the failing validate-attack-data (pull_request)

@CheraghiMilad

Copy link
Copy Markdown
Contributor Author

great! PR is looking good,. we will merge this so that we can run unit-testing in the security content repo

For now please ignore the failing validate-attack-data (pull_request)

Sure, thanks! Please let me know if there’s anything I need to do.

@CheraghiMilad

Copy link
Copy Markdown
Contributor Author

@patel-bhavin
Security-Content PR is failed becuase this merge needed. Could you merge it?

@patel-bhavin

Copy link
Copy Markdown
Collaborator

ignoring the CI failure here since it is originating from a fork! file verified manually!

@patel-bhavin
patel-bhavin merged commit 01a14ec into splunk:master Sep 3, 2025
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants