File tree Expand file tree Collapse file tree
datasets/attack_techniques/T1561.001/microsoft_intune_bulk_wipe Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -3,9 +3,11 @@ id: 4a5c3288-8391-4e80-9c3d-9dbb60ed1c45
33date : ' 2026-03-29'
44description : The following data contains simulated bulk Intune "wipe ManagedDevice" events from the Intune admin portal.
55environment : attack_range
6- dataset :
7- - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1561.001/microsoft_intune_bulk_wipe/microsoft_intune_bulk_wipe.log
8- sourcetypes :
9- - azure:monitor:activity
10- references :
11- - https://www.lumos.com/blog/stryker-hack
6+ directory : microsoft_intune_bulk_wipe
7+ mitre_technique :
8+ - T1561.001
9+ datasets :
10+ - name : microsoft_intune_bulk_wipe
11+ path : /datasets/attack_techniques/T1561.001/microsoft_intune_bulk_wipe/microsoft_intune_bulk_wipe.log
12+ sourcetype : azure:monitor:activity
13+ source : not_applicable
You can’t perform that action at this time.
0 commit comments