Files
atomic-red-team/atomics/T1124/T1124.yaml
T

40 lines
1.1 KiB
YAML
Raw Normal View History

2018-05-25 08:15:00 -04:00
attack_technique: T1124
display_name: System Time Discovery
atomic_tests:
- name: System Time Discovery
auto_generated_guid: 20aba24b-e61f-4b26-b4ce-4784f763ca20
2018-05-25 08:15:00 -04:00
description: |
Identify the system time. Upon execution, the local computer system time and timezone will be displayed.
2018-05-25 08:15:00 -04:00
supported_platforms:
- windows
2018-05-25 08:15:00 -04:00
input_arguments:
2018-05-27 15:42:23 +01:00
computer_name:
2018-05-25 08:15:00 -04:00
description: computer name to query
type: String
2019-12-02 10:54:21 -06:00
default: localhost
2018-05-25 08:15:00 -04:00
executor:
command: |
2018-08-31 07:59:05 -04:00
net time \\#{computer_name}
2018-05-25 08:15:00 -04:00
w32tm /tz
name: command_prompt
2018-05-25 08:15:00 -04:00
- name: System Time Discovery - PowerShell
auto_generated_guid: 1d5711d6-655c-4a47-ae9c-6503c74fa877
2018-05-25 08:15:00 -04:00
description: |
Identify the system time via PowerShell. Upon execution, the system time will be displayed.
2018-05-25 08:15:00 -04:00
supported_platforms:
- windows
2018-05-25 08:15:00 -04:00
executor:
command: |
2018-09-05 11:35:24 -04:00
Get-Date
name: powershell
- name: System Time Discovery in macOS
auto_generated_guid: f449c933-0891-407f-821e-7916a21a1a6f
description: |
Identify system time. Upon execution, the local computer system time and timezone will be displayed.
supported_platforms:
- macos
executor:
command: |
date
name: sh