Skip to content

Commit

Permalink
Sample O365 and Box Data
Browse files Browse the repository at this point in the history
  • Loading branch information
checkmate360 committed Jul 31, 2024
1 parent 4ac5e14 commit 3625e6e
Show file tree
Hide file tree
Showing 5,043 changed files with 264,548 additions and 0 deletions.
The diff you're trying to view is too large. We only load the first 3000 changed files.
Empty file added data/box/box_translated.json
Empty file.
11 changes: 11 additions & 0 deletions data/box/file_hosting_activity.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"_": {
"category_name": "Application Activity",
"category_uid": 6,
"class_name": "File Hosting Activity",
"class_uid": 6006,
"metadata": {
"profiles": []
}
}
}
35 changes: 35 additions & 0 deletions data/box/logs/malicious1.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
{
"type": "event",
"created_at": "2023-01-19T12:21:15",
"recorded_at": "2023-01-19T12:21:15",
"event_id": "f82c3ba03e41f7e8a7608363cc6c0390183c3f83",
"created_by": {
"id": "11446498",
"type": "user",
"name": "Admin 3",
"login": "[email protected]"
},
"event_type": "ITEM_DOWNLOAD",
"session_id": "70090280850c8d2a1933c1",
"source": {
"id": "11446498",
"type": "file",
"name": "Q1.pdf",
"created_at": "2012-12-12T10:53:43-08:00",
"modified_at": "2012-12-12T10:53:43-08:00",
"language": "en",
"timezone": "Africa/Bujumbura",
"space_amount": 11345156112,
"space_used": 1237009912,
"max_upload_size": 2147483648
},
"parent": {
"type": "folder",
"id": "1122334455",
"name": "Quarterly_Reports"
},
"ip_address": "1.2.3.4",
"additional_details": {
"key": "value"
}
}
35 changes: 35 additions & 0 deletions data/box/logs/malicious2.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
{
"type": "event",
"created_at": "2023-01-19T12:23:30",
"recorded_at": "2023-01-19T12:23:30",
"event_id": "f82c3ba03e41f7e8a7608363cc6c0390183c3f83",
"created_by": {
"id": "11446498",
"type": "user",
"name": "Admin 3",
"login": "[email protected]"
},
"event_type": "ITEM_DOWNLOAD",
"session_id": "70090280850c8d2a1933c1",
"source": {
"id": "11446498",
"type": "file",
"name": "Q2.pdf",
"created_at": "2012-12-12T10:53:43-08:00",
"modified_at": "2012-12-12T10:53:43-08:00",
"language": "en",
"timezone": "Africa/Bujumbura",
"space_amount": 11345156112,
"space_used": 1237009912,
"max_upload_size": 2147483648
},
"parent": {
"type": "folder",
"id": "1122334455",
"name": "Quarterly_Reports"
},
"ip_address": "1.2.3.4",
"additional_details": {
"key": "value"
}
}
87 changes: 87 additions & 0 deletions data/box/rule.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
{
"desc": "Translates Box Events",
"title": "Box Rule Translation",
"min_os_version": "Unknown",
"event_versions": [
{"0": "Unknown"}
],
"rules": [
{
"@include": [
"schema_version.json",
"file_hosting_activity.json"
]
},
{
"created_at": {
"@move": "time"
}
},
{
"event_type" : {
"@lookup": {
"name" : "activity_id",
"values" : {
"ITEM_UPLOAD" : 1,
"ITEM_DOWNLOAD" : 2,
"ITEM_COPY" : 6
},
"default" : 99,
"other" : "activity_name"
}
}
},
{
"event_type" : {
"@enum": {
"name" : "activity_name",
"values" : {
"ITEM_UPLOAD" : "Upload",
"ITEM_DOWNLOAD": "Download",
"ITEM_COPY" : "Copy"
},
"other" : "activity_name"
}
}
},
{
"created_by.login" : {
"@move" : "actor.user.email_addr"
}
},
{
"ip_address" : {
"@move" : "src_endpoint.ip"
}
},
{
"source.type" : {
"@enum": {
"name" : "file.type_id",
"values" : {
"File" : 1,
"Folder" : 2
},
"default" : 99,
"other" : "file.type"
}
}
},
{
"source.space_used" : {
"@move" : "file.size"
}
},
{
"source.name" : {
"@move" : "file.name"
}
},
{
"parent.name" : {
"@move" : "file.parent_folder"
}
}

]
}
10 changes: 10 additions & 0 deletions data/box/schema_version.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
{
"_": {
"description": "Defines the schema version used in the translations.",
"@value": {
"metadata": {
"version": "1.0.0-rc.3"
}
}
}
}
11 changes: 11 additions & 0 deletions data/o365/file_hosting_activity.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"_": {
"category_name": "Application Activity",
"category_uid": 6,
"class_name": "File Hosting Activity",
"class_uid": 6006,
"metadata": {
"profiles": []
}
}
}
34 changes: 34 additions & 0 deletions data/o365/logs/json_0.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
{
"AppAccessContext": {
"AADSessionId": "00000000-0000-0000-0000-000000000000",
"CorrelationId": "00000000-0000-0000-0000-000000000000"
},
"CreationTime": "2023-01-24T14:21:15",
"Id": "00000000-0000-0000-0000-000000000000",
"Operation": "FileModifiedExtended",
"OrganizationId": "00000000-0000-0000-0000-000000000000",
"RecordType": 6,
"UserKey": "i:0h.f|membership|[email protected]",
"UserType": 0,
"Version": 1,
"Workload": "OneDrive",
"ClientIP": "1.2.3.4",
"ObjectId": "https://gravywhale.sharepoint.com/sites/Nashville/SiteAssets/file.docx",
"UserId": "[email protected]",
"CorrelationId": "00000000-0000-0000-0000-000000000000",
"EventSource": "SharePoint",
"ItemType": "File",
"ListId": "00000000-0000-0000-0000-000000000000",
"ListItemUniqueId": "00000000-0000-0000-0000-000000000000",
"Site": "00000000-0000-0000-0000-000000000000",
"UserAgent": "MSWAC",
"WebId": "00000000-0000-0000-0000-000000000000",
"FileSizeBytes": 2667962,
"SourceFileExtension": "pptx",
"SiteUrl": "https://gravywhale.sharepoint.com/sites/Nashville/",
"SourceFileName": "Becuase I Said So.docx",
"SourceRelativeUrl": "Documents/Desktop",
"AssociatedAdminUnits": [
"00000000-0000-0000-0000-000000000000"
]
}
72 changes: 72 additions & 0 deletions data/o365/logs/json_1.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
{
"CreationTime": "2023-01-24T14:21:15",
"Id": "00000000-0000-0000-0000-000000000000",
"Operation": "UserLoggedIn",
"OrganizationId": "00000000-0000-0000-0000-000000000000",
"RecordType": 15,
"ResultStatus": "Success",
"UserKey": "00000000-0000-0000-0000-000000000000",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ClientIP": "1.2.3.4",
"ObjectId": "00000000-0000-0000-0000-000000000000",
"UserId": "[email protected]",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "ResultStatusDetail",
"Value": "Redirect"
},
{
"Name": "UserAgent",
"Value": "Mozilla/5.0 (X11; CrOS x86_64 14816.131.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
},
{
"Name": "RequestType",
"Value": "OAuth2:Authorize"
}
],
"ModifiedProperties": [],
"Actor": [
{
"ID": "00000000-0000-0000-0000-000000000000",
"Type": 0
},
{
"ID": "[email protected]",
"Type": 5
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000000",
"ActorIpAddress": "1.2.3.4",
"InterSystemsId": "00000000-0000-0000-0000-000000000000",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"SupportTicketId": "",
"Target": [
{
"ID": "00000000-0000-0000-0000-000000000000",
"Type": 0
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000000",
"ApplicationId": "00000000-0000-0000-0000-000000000000",
"DeviceProperties": [
{
"Name": "BrowserType",
"Value": "Chrome"
},
{
"Name": "IsCompliantAndManaged",
"Value": "False"
},
{
"Name": "SessionId",
"Value": "00000000-0000-0000-0000-000000000000"
}
],
"ErrorNumber": "0",
"AssociatedAdminUnits": [
"00000000-0000-0000-0000-000000000000"
]
}
36 changes: 36 additions & 0 deletions data/o365/logs/json_10.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"AppAccessContext": {
"CorrelationId": "00000000-0000-0000-0000-000000000000",
"UniqueTokenId": "0000000000000000000000"
},
"CreationTime": "2023-01-24T14:21:15",
"Id": "00000000-0000-0000-0000-000000000000",
"Operation": "FileAccessedExtended",
"OrganizationId": "00000000-0000-0000-0000-000000000000",
"RecordType": 6,
"UserKey": "i:0h.f|membership|[email protected]",
"UserType": 0,
"Version": 1,
"Workload": "SharePoint",
"ClientIP": "1.2.3.4",
"ObjectId": "https://gravywhale.sharepoint.com/sites/Nashville/SiteAssets/file.docx",
"UserId": "[email protected]",
"CorrelationId": "00000000-0000-0000-0000-000000000000",
"EventSource": "SharePoint",
"ItemType": "File",
"ListId": "00000000-0000-0000-0000-000000000000",
"ListItemUniqueId": "00000000-0000-0000-0000-000000000000",
"Site": "00000000-0000-0000-0000-000000000000",
"UserAgent": "MSWAC",
"WebId": "00000000-0000-0000-0000-000000000000",
"HighPriorityMediaProcessing": false,
"IsManagedDevice": true,
"SourceFileExtension": "docx",
"SiteUrl": "https://gravywhale.sharepoint.com/sites/Nashville/",
"SourceFileName": "Becuase I Said So.docx",
"SourceRelativeUrl": "Documents/Desktop",
"AssociatedAdminUnits": [
"00000000-0000-0000-0000-000000000000",
"00000000-0000-0000-0000-000000000000"
]
}
Loading

0 comments on commit 3625e6e

Please sign in to comment.