From 5c06969d6d21073fbcc8492bfe633b0036b131d8 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Mon, 10 Feb 2025 10:57:01 -0500 Subject: [PATCH] Initial upload --- .../bitlocker_sus_commands.log | 3 +++ .../bitlocker_sus_commands.yml | 14 ++++++++++++++ 2 files changed, 17 insertions(+) create mode 100644 datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.log create mode 100644 datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.yml diff --git a/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.log b/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.log new file mode 100644 index 00000000..55abddbf --- /dev/null +++ b/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.log @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:9e1e4b875d2ae27e4b2c99e6403cf2f642d087f415af2a06c0b63e0556110002 +size 2002 diff --git a/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.yml b/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.yml new file mode 100644 index 00000000..2276d77d --- /dev/null +++ b/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.yml @@ -0,0 +1,14 @@ +author: Steven Dick +id: 2cf75567-0739-4cd2-8d83-fd5c0177045e +date: '2025-02-10' +description: 'A sample event with a known abusedd manage-bde command.' +environment: attack_range +dataset: +- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/bitlocker_sus_commands/bitlocker_sus_commands.log +sourcetypes: +- XmlWinEventLog +references: +- https://attack.mitre.org/techniques/T1486/ +- https://www.nccgroup.com/us/research-blog/nameless-and-shameless-ransomware-encryption-via-bitlocker/ +- https://www.bitdefender.com/en-us/blog/businessinsights/shrinklocker-decryptor-from-friend-to-foe-and-back-again +- https://www.bleepingcomputer.com/news/security/new-shrinklocker-ransomware-uses-bitlocker-to-encrypt-your-files/ \ No newline at end of file