Skip to content

Commit d35fbe5

Browse files
committed
adding attack data
1 parent d3ada92 commit d35fbe5

File tree

4 files changed

+29
-0
lines changed

4 files changed

+29
-0
lines changed
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Bhavin Patel
2+
id: 984e9022-b87b-499a-a260-8d0282c46ea2
3+
date: '2025-04-10'
4+
description: Dataset generated from AWS CloudTrail logs capturing the lifecycle of an intentionally exposed S3 bucket, including its creation, public access configuration (via bucket policy and website hosting), and subsequent deletion. This simulates the an activity of a malicious actor deleting a knowledge base from AWS Bedrock.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/aws_delete_knowledge_base/cloudtrail.json
8+
sourcetypes:
9+
- aws:cloudtrail
10+
references:
11+
- https://attack.mitre.org/techniques/T1485/
12+
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:9bcaa0a91ea6e97cdc51b6ef6af0258068bab369226a72bfb94dca535d235d9a
3+
size 1559
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: Bhavin Patel, Splunk
2+
id: cdd4205f-e570-42ee-add9-048f2ac48a62
3+
date: '2025-04-10'
4+
description: Dataset which contains cloudtrail events with a deletes of AWS Bedrock GuardRails
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_bedrock_delete_guardrails/cloudtrail.json
8+
sourcetypes:
9+
- aws:cloudtrail
10+
references:
11+
- https://attack.mitre.org/techniques/T1562/008/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:c2fac3e16c8fc17ae01c697fbd8eb92ba1fc4386547f7f14652d3da8d6f61cd2
3+
size 1554

0 commit comments

Comments
 (0)