Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nterl0k - T1567 - Suspect File Exfiltration Behaviors #3298

Merged
merged 22 commits into from
Feb 19, 2025
Merged
Changes from 1 commit
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
f74a15d
Add files via upload
nterl0k Jan 28, 2025
e29b0b3
Update o365_exfiltration_via_file_sync_download.yml
nterl0k Jan 28, 2025
8297766
Update o365_exfiltration_via_file_download.yml
nterl0k Jan 28, 2025
039ef36
Update o365_exfiltration_via_file_access.yml
nterl0k Jan 28, 2025
2fdbb80
Update o365_exfiltration_via_file_access.yml
nterl0k Jan 28, 2025
2f99dd1
Update o365_exfiltration_via_file_download.yml
nterl0k Jan 28, 2025
bef252a
Update o365_exfiltration_via_file_sync_download.yml
nterl0k Jan 28, 2025
7a00c05
Update o365_exfiltration_via_file_access.yml
nterl0k Jan 31, 2025
38c3f57
Update o365_exfiltration_via_file_download.yml
nterl0k Jan 31, 2025
a136609
Update o365_exfiltration_via_file_sync_download.yml
nterl0k Jan 31, 2025
842ee12
Update o365_exfiltration_via_file_access.yml
nterl0k Jan 31, 2025
0e8ac8a
Update o365_exfiltration_via_file_download.yml
nterl0k Jan 31, 2025
ae1b755
Update o365_exfiltration_via_file_sync_download.yml
nterl0k Jan 31, 2025
8cc8402
Merge branch 'develop' into nterl0k-t1567-o365-sus-file-exfil
patel-bhavin Jan 31, 2025
9de8908
Update o365_exfiltration_via_file_access.yml
nterl0k Feb 2, 2025
84c1a4c
Update o365_exfiltration_via_file_download.yml
nterl0k Feb 2, 2025
1ac26e3
Update o365_exfiltration_via_file_sync_download.yml
nterl0k Feb 2, 2025
cf69152
Merge branch 'develop' into nterl0k-t1567-o365-sus-file-exfil
nasbench Feb 5, 2025
0a2bdd0
Merge branch 'splunk:develop' into nterl0k-t1567-o365-sus-file-exfil
nterl0k Feb 14, 2025
558f898
Merge branch 'develop' into nterl0k-t1567-o365-sus-file-exfil
patel-bhavin Feb 18, 2025
5232702
Merge branch 'develop' into nterl0k-t1567-o365-sus-file-exfil
patel-bhavin Feb 19, 2025
7c402fa
Merge branch 'develop' into nterl0k-t1567-o365-sus-file-exfil
patel-bhavin Feb 19, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Update o365_exfiltration_via_file_sync_download.yml
nterl0k authored Jan 28, 2025

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
commit e29b0b3f01f071cfda420131f26ad73b148fb7e1
Original file line number Diff line number Diff line change
@@ -74,4 +74,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1567/o365_sus_file_activity/o365_sus_file_activity.log
source: o365
sourcetype: o365:management:activity
sourcetype: o365:management:activity