Skip to content

Commit f5e7249

Browse files
committed
added atc-data as submodule
1 parent 9e89eea commit f5e7249

File tree

319 files changed

+828
-7911
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

319 files changed

+828
-7911
lines changed

.gitmodules

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,3 +10,6 @@
1010
[submodule "response/atc_react"]
1111
path = response/atc_react
1212
url = https://github.com/atc-project/atc-react
13+
[submodule "data/atc_data"]
14+
path = data/atc_data
15+
url = https://github.com/atc-project/atc-data

Atomic_Threat_Coverage/Data_Needed/DN_0001_4688_windows_process_creation.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0001_4688_windows_process_creation.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
1-
| Title | DN_0001_4688_windows_process_creation |
1+
| Title | DN0001_4688_windows_process_creation |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | Windows process creation log, not including command line |
4-
| **Logging Policy** | <ul><li>[LP_0001_windows_audit_process_creation](../Logging_Policies/LP_0001_windows_audit_process_creation.md)</li></ul> |
5+
| **Logging Policy** | <ul><li>[LP0001_windows_audit_process_creation](../Logging_Policies/LP0001_windows_audit_process_creation.md)</li></ul> |
56
| **References** | <ul><li>[https://github.com/MicrosoftDocs/windows-itpro-docs/blob/95b9d7c01805839c067e352d1d16702604b15f11/windows/security/threat-protection/auditing/event-4688.md](https://github.com/MicrosoftDocs/windows-itpro-docs/blob/95b9d7c01805839c067e352d1d16702604b15f11/windows/security/threat-protection/auditing/event-4688.md)</li></ul> |
67
| **Platform** | Windows |
78
| **Type** | Windows Log |

Atomic_Threat_Coverage/Data_Needed/DN_0002_4688_windows_process_creation_with_commandline.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0002_4688_windows_process_creation_with_commandline.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
1-
| Title | DN_0002_4688_windows_process_creation_with_commandline |
1+
| Title | DN0002_4688_windows_process_creation_with_commandline |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | Windows process creation log, including command line |
4-
| **Logging Policy** | <ul><li>[LP_0001_windows_audit_process_creation](../Logging_Policies/LP_0001_windows_audit_process_creation.md)</li><li>[LP_0002_windows_audit_process_creation_with_commandline](../Logging_Policies/LP_0002_windows_audit_process_creation_with_commandline.md)</li></ul> |
5+
| **Logging Policy** | <ul><li>[LP0001_windows_audit_process_creation](../Logging_Policies/LP0001_windows_audit_process_creation.md)</li><li>[LP0002_windows_audit_process_creation_with_commandline](../Logging_Policies/LP0002_windows_audit_process_creation_with_commandline.md)</li></ul> |
56
| **References** | <ul><li>[https://github.com/MicrosoftDocs/windows-itpro-docs/blob/95b9d7c01805839c067e352d1d16702604b15f11/windows/security/threat-protection/auditing/event-4688.md](https://github.com/MicrosoftDocs/windows-itpro-docs/blob/95b9d7c01805839c067e352d1d16702604b15f11/windows/security/threat-protection/auditing/event-4688.md)</li></ul> |
67
| **Platform** | Windows |
78
| **Type** | Windows Log |

Atomic_Threat_Coverage/Data_Needed/DN_0003_1_windows_sysmon_process_creation.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0003_1_windows_sysmon_process_creation.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
1-
| Title | DN_0003_1_windows_sysmon_process_creation |
1+
| Title | DN0003_1_windows_sysmon_process_creation |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | Windows process creation log, including command line |
4-
| **Logging Policy** | <ul><li>[LP_0003_windows_sysmon_process_creation](../Logging_Policies/LP_0003_windows_sysmon_process_creation.md)</li></ul> |
5+
| **Logging Policy** | <ul><li>[LP0003_windows_sysmon_process_creation](../Logging_Policies/LP0003_windows_sysmon_process_creation.md)</li></ul> |
56
| **References** | <ul><li>[https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90001](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90001)</li></ul> |
67
| **Platform** | Windows |
78
| **Type** | Applications and Services Logs |

Atomic_Threat_Coverage/Data_Needed/DN_0004_4624_windows_account_logon.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0004_4624_windows_account_logon.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
1-
| Title | DN_0004_4624_windows_account_logon |
1+
| Title | DN0004_4624_windows_account_logon |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | An account was successfully logged on |
4-
| **Logging Policy** | <ul><li>[LP_0004_windows_audit_logon](../Logging_Policies/LP_0004_windows_audit_logon.md)</li></ul> |
5+
| **Logging Policy** | <ul><li>[LP0004_windows_audit_logon](../Logging_Policies/LP0004_windows_audit_logon.md)</li></ul> |
56
| **References** | <ul><li>[https://github.com/MicrosoftDocs/windows-itpro-docs/blob/95b9d7c01805839c067e352d1d16702604b15f11/windows/security/threat-protection/auditing/event-4624.md](https://github.com/MicrosoftDocs/windows-itpro-docs/blob/95b9d7c01805839c067e352d1d16702604b15f11/windows/security/threat-protection/auditing/event-4624.md)</li></ul> |
67
| **Platform** | Windows |
78
| **Type** | Windows Log |

Atomic_Threat_Coverage/Data_Needed/DN_0005_7045_windows_service_insatalled.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0005_7045_windows_service_insatalled.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
1-
| Title | DN_0005_7045_windows_service_insatalled |
1+
| Title | DN0005_7045_windows_service_insatalled |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | A service was installed in the system |
45
| **Logging Policy** | <ul><li> Not existing </li></ul> |
56
| **References** | <ul><li>[None](None)</li></ul> |
Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
1-
| Title | DN_0006_2_windows_sysmon_process_changed_a_file_creation_time |
1+
| Title | DN0006_2_windows_sysmon_process_changed_a_file_creation_time |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | Explicit modification of file creation timestamp by a process |
45
| **Logging Policy** | <ul><li> Not existing </li></ul> |
56
| **References** | <ul><li>[https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90002](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90002)</li><li>[https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-2.md](https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-2.md)</li></ul> |

Atomic_Threat_Coverage/Data_Needed/DN_0007_3_windows_sysmon_network_connection.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0007_3_windows_sysmon_network_connection.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
1-
| Title | DN_0007_3_windows_sysmon_network_connection |
1+
| Title | DN0007_3_windows_sysmon_network_connection |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | TCP/UDP connections made by a process |
4-
| **Logging Policy** | <ul><li>[LP_0005_windows_sysmon_network_connection](../Logging_Policies/LP_0005_windows_sysmon_network_connection.md)</li></ul> |
5+
| **Logging Policy** | <ul><li>[LP0005_windows_sysmon_network_connection](../Logging_Policies/LP0005_windows_sysmon_network_connection.md)</li></ul> |
56
| **References** | <ul><li>[https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90003](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90003)</li><li>[https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-3.md](https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-3.md)</li></ul> |
67
| **Platform** | Windows |
78
| **Type** | Applications and Services Logs |

Atomic_Threat_Coverage/Data_Needed/DN_0008_4_windows_sysmon_sysmon_service_state_changed.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0008_4_windows_sysmon_sysmon_service_state_changed.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
1-
| Title | DN_0008_4_windows_sysmon_sysmon_service_state_changed |
1+
| Title | DN0008_4_windows_sysmon_sysmon_service_state_changed |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | Sysmon service changed status |
45
| **Logging Policy** | <ul><li> Not existing </li></ul> |
56
| **References** | <ul><li>[https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90004](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90004)</li><li>[https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-4.md](https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-4.md)</li></ul> |

Atomic_Threat_Coverage/Data_Needed/DN_0009_5_windows_sysmon_process_terminated.md renamed to Atomic_Threat_Coverage/Data_Needed/DN0009_5_windows_sysmon_process_terminated.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
1-
| Title | DN_0009_5_windows_sysmon_process_terminated |
1+
| Title | DN0009_5_windows_sysmon_process_terminated |
22
|:-------------------|:------------------|
3+
| **Author** | @atc_project |
34
| **Description** | Process has been terminated |
45
| **Logging Policy** | <ul><li> Not existing </li></ul> |
56
| **References** | <ul><li>[https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90005](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90005)</li></ul> |

0 commit comments

Comments
 (0)