Skip to content

Commit

Permalink
Initial upload
Browse files Browse the repository at this point in the history
  • Loading branch information
nterl0k authored Feb 10, 2025
1 parent c08731f commit 5c06969
Show file tree
Hide file tree
Showing 2 changed files with 17 additions and 0 deletions.
Git LFS file not shown
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
author: Steven Dick
id: 2cf75567-0739-4cd2-8d83-fd5c0177045e
date: '2025-02-10'
description: 'A sample event with a known abusedd manage-bde command.'
environment: attack_range
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.log
sourcetypes:
- XmlWinEventLog
references:
- https://attack.mitre.org/techniques/T1486/
- https://www.nccgroup.com/us/research-blog/nameless-and-shameless-ransomware-encryption-via-bitlocker/
- https://www.bitdefender.com/en-us/blog/businessinsights/shrinklocker-decryptor-from-friend-to-foe-and-back-again
- https://www.bleepingcomputer.com/news/security/new-shrinklocker-ransomware-uses-bitlocker-to-encrypt-your-files/

0 comments on commit 5c06969

Please sign in to comment.