log2ml/2-2-adversary-emulation-and-training-data-generation/Sysmon_Observations (1).svg

2 lines
253 KiB
XML
Raw Permalink Normal View History

<?xml version="1.0" standalone="no"?>
<svg width="1056" height="816" xmlns="http://www.w3.org/2000/svg" id="svgvm1"><g transform="translate(5,5)" style="font-family: sans-serif;"><g><g transform="translate(0, 0)"><g transform="translate(0,5)"><rect class="header-box" width="509.5897435897436" height="86" stroke="black" fill="white" rx="5"/><rect class="label-cover" x="8" y="-11" width="103.6328125" height="18.1328125" fill="white" rx="5"/><text class="header-box-label" x="10" font-size="12" fill="black" y="3">domain &amp; platforms</text><g class="header-box-content" fill="black" transform="translate(5, 0)"><g transform="translate(0, 4.095238095238102)"><text font-size="12"><tspan x="1" y="42.4047619047619">Windows</tspan></text></g></g></g></g><g transform="translate(536.4102564102565, 0)"><g transform="translate(0,5)"><rect class="header-box" width="509.5897435897436" height="86" stroke="black" fill="white" rx="5"/><rect class="label-cover" x="8" y="-11" width="53.875" height="18.1328125" fill="white" rx="5"/><text class="header-box-label" x="10" font-size="12" fill="black" y="3">aggregate</text><g class="header-box-content" fill="black" transform="translate(5, 0)"><g transform="translate(0, 4.095238095238102)"><text font-size="12"><tspan x="1" y="42.4047619047619">showing aggregate scores using the sum aggregate function</tspan></text></g></g></g></g></g><g transform="translate(0,97)"><g><g class="tactic initial-access" transform="translate(0, 0)"><g class="techniques"><g class="technique T1659" transform="translate(0, 4.6103896103896105)"><rect class="cell" height="4.6103896103896105" width="87.16666666666667" fill="#AB47BC" stroke="#6B7279"/><polygon class="sidebar" transform="translate(0, 4.6103896103896105)" points="0,0 6.220779220779221,0 6.220779220779221,0" fill="#6B7279" visibility="hidden"/><text font-size="2" fill="white"><tspan x="1" y="3.8051948051948052">Content Injection</tspan></text></g><g class="technique T1189" transform="translate(0, 9.220779220779221)"><rect class="cell" height="4.6103896103896105" width="87.16666666666667" fill="#AB47BC" stroke="#6B7279"/><polygon class="sidebar" transform="translate(0, 4.6103896103896105)" points="0,0 6.220779220779221,0 6.220779220779221,0" fill="#6B7279" visibility="hidden"/><text font-size="2" fill="white"><tspan x="1" y="3.8051948051948052">Drive-by Compromise</tspan></text></g><g class="technique T1190" transform="translate(0, 13.831168831168831)"><rect class="cell" height="4.6103896103896105" width="87.16666666666667" fill="#ffffff" stroke="#6B7279"/><polygon class="sidebar" transform="translate(0, 4.6103896103896105)" points="0,0 6.220779220779221,0 6.220779220779221,0" fill="#6B7279" visibility="hidden"/><text font-size="2" fill="#000000"><tspan x="1" y="3.8051948051948052">Exploit Public-Facing Application</tspan></text></g><g class="technique T1133" transform="translate(0, 18.441558441558442)"><rect class="cell" height="4.6103896103896105" width="87.16666666666667" fill="#E1BEE7" stroke="#6B7279"/><polygon class="sidebar" transform="translate(0, 4.6103896103896105)" points="0,0 6.220779220779221,0 6.220779220779221,0" fill="#6B7279" visibility="hidden"/><text font-size="2" fill="black"><tspan x="1" y="3.8051948051948052">External Remote Services</tspan></text></g><g class="technique T1200" transform="translate(0, 23.05194805194805)"><rect class="cell" height="4.6103896103896105" width="87.16666666666667" fill="#ffffff" stroke="#6B7279"/><polygon class="sidebar" transform="translate(0, 4.6103896103896105)" points="0,0 6.220779220779221,0 6.220779220779221,0" fill="#6B7279" visibility="hidden"/><text font-size="2" fill="#000000"><tspan x="1" y="3.8051948051948052">Hardware Additions</tspan></text></g><g class="technique T1566" transform="translate(0, 27.662337662337663)"><rect class="cell" height="4.6103896103896105" width="87.16666666666667" fill="#E1BEE7" stroke="#6B7279"/><polygon class="sidebar" transform="translate(0, 4.6103896103896105)" points="0,0 6.220779220779221,0 6.220779220779221,6.220779220779221" fill="#6B7279" visibility="visible"/><text font-size="2" fill="black"><tspan x="1