diff --git a/atomics/T1003.001/T1003.001.yaml b/atomics/T1003.001/T1003.001.yaml index 41da559c..4c41e0bd 100644 --- a/atomics/T1003.001/T1003.001.yaml +++ b/atomics/T1003.001/T1003.001.yaml @@ -383,6 +383,7 @@ atomic_tests: name: powershell elevation_required: true - name: Dump LSASS.exe Memory through Silent Process Exit + auto_generated_guid: eb5adf16-b601-4926-bca7-dad22adffb37 description: | WerFault.exe (Windows Error Reporting process that handles process crashes) can be abused to create a memory dump of lsass.exe, in a directory of your choice. This method relies on a mechanism diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index c9c960f7..1dd6ae22 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1504,3 +1504,4 @@ a72cfef8-d252-48b3-b292-635d332625c3 4f3c7502-b111-4dfe-8a6e-529307891a59 2170d9b5-bacd-4819-a952-da76dae0815f 87fffff4-d371-4057-a539-e3b24c37e564 +eb5adf16-b601-4926-bca7-dad22adffb37