Generated docs from job=generate-docs branch=master [ci skip]

This commit is contained in:
Atomic Red Team doc generator
2026-04-16 02:44:12 +00:00
parent e54d19d85a
commit 929d64a1b7
5 changed files with 28 additions and 20 deletions
+6 -4
View File
@@ -2049,8 +2049,9 @@ defense-evasion:
$bytes = [System.Convert]::FromBase64String($encodedString)
$decodedString = [System.Text.Encoding]::UTF8.GetString($bytes)
#write the decoded eicar string to file
$decodedString | Out-File T1027.013_decodedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decodedEicar.txt file.
$decodedString | Out-File $env:temp\T1027.013_decodedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decodedEicar.txt -Force -ErrorAction
Ignore
name: powershell
elevation_required: false
- name: Decrypt Eicar File and Write to File
@@ -2068,8 +2069,9 @@ defense-evasion:
$decrypt = ConvertTo-SecureString -String $encryptedString -Key $key
$decryptedString = [Runtime.InteropServices.Marshal]::PtrToStringBSTR([Runtime.InteropServices.Marshal]::SecureStringToBSTR($decrypt))
#Write the decrypted eicar string to a file
$decryptedString | out-file T1027.013_decryptedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decryptedEicar.txt file.
$decryptedString | Out-File $env:temp\T1027.013_decryptedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decryptedEicar.txt -Force
-ErrorAction Ignore
name: powershell
elevation_required: false
- name: Password-Protected ZIP Payload Extraction and Execution
+6 -4
View File
@@ -1530,8 +1530,9 @@ defense-evasion:
$bytes = [System.Convert]::FromBase64String($encodedString)
$decodedString = [System.Text.Encoding]::UTF8.GetString($bytes)
#write the decoded eicar string to file
$decodedString | Out-File T1027.013_decodedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decodedEicar.txt file.
$decodedString | Out-File $env:temp\T1027.013_decodedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decodedEicar.txt -Force -ErrorAction
Ignore
name: powershell
elevation_required: false
- name: Decrypt Eicar File and Write to File
@@ -1549,8 +1550,9 @@ defense-evasion:
$decrypt = ConvertTo-SecureString -String $encryptedString -Key $key
$decryptedString = [Runtime.InteropServices.Marshal]::PtrToStringBSTR([Runtime.InteropServices.Marshal]::SecureStringToBSTR($decrypt))
#Write the decrypted eicar string to a file
$decryptedString | out-file T1027.013_decryptedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decryptedEicar.txt file.
$decryptedString | Out-File $env:temp\T1027.013_decryptedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decryptedEicar.txt -Force
-ErrorAction Ignore
name: powershell
elevation_required: false
- name: Password-Protected ZIP Payload Extraction and Execution
+6 -4
View File
@@ -1329,8 +1329,9 @@ defense-evasion:
$bytes = [System.Convert]::FromBase64String($encodedString)
$decodedString = [System.Text.Encoding]::UTF8.GetString($bytes)
#write the decoded eicar string to file
$decodedString | Out-File T1027.013_decodedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decodedEicar.txt file.
$decodedString | Out-File $env:temp\T1027.013_decodedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decodedEicar.txt -Force -ErrorAction
Ignore
name: powershell
elevation_required: false
- name: Decrypt Eicar File and Write to File
@@ -1348,8 +1349,9 @@ defense-evasion:
$decrypt = ConvertTo-SecureString -String $encryptedString -Key $key
$decryptedString = [Runtime.InteropServices.Marshal]::PtrToStringBSTR([Runtime.InteropServices.Marshal]::SecureStringToBSTR($decrypt))
#Write the decrypted eicar string to a file
$decryptedString | out-file T1027.013_decryptedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decryptedEicar.txt file.
$decryptedString | Out-File $env:temp\T1027.013_decryptedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decryptedEicar.txt -Force
-ErrorAction Ignore
name: powershell
elevation_required: false
- name: Password-Protected ZIP Payload Extraction and Execution
+6 -4
View File
@@ -1524,8 +1524,9 @@ defense-evasion:
$bytes = [System.Convert]::FromBase64String($encodedString)
$decodedString = [System.Text.Encoding]::UTF8.GetString($bytes)
#write the decoded eicar string to file
$decodedString | Out-File T1027.013_decodedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decodedEicar.txt file.
$decodedString | Out-File $env:temp\T1027.013_decodedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decodedEicar.txt -Force -ErrorAction
Ignore
name: powershell
elevation_required: false
- name: Decrypt Eicar File and Write to File
@@ -1543,8 +1544,9 @@ defense-evasion:
$decrypt = ConvertTo-SecureString -String $encryptedString -Key $key
$decryptedString = [Runtime.InteropServices.Marshal]::PtrToStringBSTR([Runtime.InteropServices.Marshal]::SecureStringToBSTR($decrypt))
#Write the decrypted eicar string to a file
$decryptedString | out-file T1027.013_decryptedEicar.txt
cleanup_command: Just delete the resulting T1027.013_decryptedEicar.txt file.
$decryptedString | Out-File $env:temp\T1027.013_decryptedEicar.txt
cleanup_command: Remove-Item $env:temp\T1027.013_decryptedEicar.txt -Force
-ErrorAction Ignore
name: powershell
elevation_required: false
T1014:
+4 -4
View File
@@ -35,13 +35,13 @@ $encodedString = "WDVPIVAlQEFQWzRcUFpYNTQoUF4pN0NDKTd9JEVJQ0FSLVNUQU5EQVJELUFOVE
$bytes = [System.Convert]::FromBase64String($encodedString)
$decodedString = [System.Text.Encoding]::UTF8.GetString($bytes)
#write the decoded eicar string to file
$decodedString | Out-File T1027.013_decodedEicar.txt
$decodedString | Out-File $env:temp\T1027.013_decodedEicar.txt
```
#### Cleanup Commands
```powershell
Just delete the resulting T1027.013_decodedEicar.txt file.
Remove-Item $env:temp\T1027.013_decodedEicar.txt -Force -ErrorAction Ignore
```
### Atomic Test #2: Decrypt Eicar File and Write to File
@@ -59,13 +59,13 @@ $key = [byte]1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,2
$decrypt = ConvertTo-SecureString -String $encryptedString -Key $key
$decryptedString = [Runtime.InteropServices.Marshal]::PtrToStringBSTR([Runtime.InteropServices.Marshal]::SecureStringToBSTR($decrypt))
#Write the decrypted eicar string to a file
$decryptedString | out-file T1027.013_decryptedEicar.txt
$decryptedString | Out-File $env:temp\T1027.013_decryptedEicar.txt
```
#### Cleanup Commands
```powershell
Just delete the resulting T1027.013_decryptedEicar.txt file.
Remove-Item $env:temp\T1027.013_decryptedEicar.txt -Force -ErrorAction Ignore
```
### Atomic Test #3: Password-Protected ZIP Payload Extraction and Execution