Skip to content

Commit 93664fc

Browse files
authored
Merge pull request #1162 from splunk/active_mq_exploit
new dataset for ActiveMQ exploit and Lockbit ransomware
2 parents b26e281 + 260aa80 commit 93664fc

4 files changed

Lines changed: 28 additions & 0 deletions

File tree

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
author: Patrick Bareiss, Splunk
2+
id: 1d5e15bc-7eaf-46a2-8a92-ad9e3eb5cbb4
3+
date: '2026-04-28'
4+
description: Execution of ActiveMQ exploit and Lockbit ransomware based on the following DFIR report https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/
5+
environment: attack_range
6+
directory: ActiveMQ_exploit_Lockbit_Ransomware
7+
datasets:
8+
- name: windows-sysmon
9+
path: /datasets/apt_simulations/ActiveMQ_exploit_Lockbit_Ransomware/windows-sysmon.log
10+
sourcetype: XmlWinEventLog
11+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
12+
- name: windows-security
13+
path: /datasets/apt_simulations/ActiveMQ_exploit_Lockbit_Ransomware/windows-security.log
14+
sourcetype: XmlWinEventLog
15+
source: XmlWinEventLog:Security
16+
- name: windows-powershell
17+
path: /datasets/apt_simulations/ActiveMQ_exploit_Lockbit_Ransomware/windows-powershell.log
18+
sourcetype: XmlWinEventLog
19+
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:405c2a15b183abd9f23e22eb18ddb65b562d9b80cca7a4338ffeddc26cbb6c4c
3+
size 57064933
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:55555312391cf49c51fddbbd2c19aa09d7c1469205d0f3374bec68ad4df49a78
3+
size 21544480
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:6fb7acc46cae31504b1d8fc7b731cfcbbfc61ef9819574a72d684c8ea47e9360
3+
size 20699440

0 commit comments

Comments
 (0)