Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nterl0k - Goot Loader Malware w/ Partial TTPs #817

Merged
merged 4 commits into from
Jul 11, 2023

Conversation

nterl0k
Copy link
Contributor

@nterl0k nterl0k commented Jun 15, 2023

Upload for incoming detection builds.

@nterl0k nterl0k changed the title Nterl0k - Goot Loader Malware Partial ttps Nterl0k - Goot Loader Malware w/ Partial TTPs Jun 15, 2023
Add registry data similar to previously seen versions of goot
@patel-bhavin
Copy link
Collaborator

patel-bhavin commented Jul 11, 2023

@nterl0k : Hello, thank you for the PR. Can you add a yml file in the partial_ttps directory describing the data, how it was generated?
Also, it looks like the .log file was directly committed into the branch. Upload these dataset files via git lfs?
Eg: https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1003.001/atomic_red_team/atomic_red_team.yml

@nterl0k
Copy link
Contributor Author

nterl0k commented Jul 11, 2023 via email

@nterl0k
Copy link
Contributor Author

nterl0k commented Jul 11, 2023

yml added, edit/update as you need to.

@patel-bhavin
Copy link
Collaborator

perfect! this is great. thank you for being so prompt! @nterl0k

@patel-bhavin patel-bhavin merged commit 7d4925c into splunk:master Jul 11, 2023
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants