diff --git a/atomics/T1547.003/T1547.003.yaml b/atomics/T1547.003/T1547.003.yaml index e0dedc88..6acb6268 100644 --- a/atomics/T1547.003/T1547.003.yaml +++ b/atomics/T1547.003/T1547.003.yaml @@ -2,6 +2,7 @@ attack_technique: T1547.003 display_name: Time Providers atomic_tests: - name: Create a new time provider + auto_generated_guid: df1efab7-bc6d-4b88-8be9-91f55ae017aa description: | Establishes persistence by creating a new time provider registry key under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider. @@ -26,6 +27,7 @@ atomic_tests: elevation_required: true - name: Edit an existing time provider + auto_generated_guid: 29e0afca-8d1d-471a-8d34-25512fc48315 description: | Establishes persistence by editing the NtpServer time provider registry key under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index fe1432f0..a5d8863b 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1064,3 +1064,5 @@ fecd0dfd-fb55-45fa-a10b-6250272d0832 cd925593-fbb4-486d-8def-16cbdf944bf4 4d66029d-7355-43fd-93a4-b63ba92ea1be 123520cc-e998-471b-a920-bd28e3feafa0 +df1efab7-bc6d-4b88-8be9-91f55ae017aa +29e0afca-8d1d-471a-8d34-25512fc48315