diff --git a/atomics/T1553.005/T1553.005.yaml b/atomics/T1553.005/T1553.005.yaml index 0f1a8003..58ca514d 100644 --- a/atomics/T1553.005/T1553.005.yaml +++ b/atomics/T1553.005/T1553.005.yaml @@ -61,6 +61,7 @@ atomic_tests: name: powershell - name: Remove the Zone.Identifier alternate data stream + auto_generated_guid: 64b12afc-18b8-4d3f-9eab-7f6cae7c73f9 description: | Remove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet. Removing this allows more freedom in executing scripts in PowerShell and avoids opening files in protected view. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 93edac9d..47319e8f 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -781,3 +781,4 @@ bc071188-459f-44d5-901a-f8f2625b2d2e d1253f6e-c29b-49dc-b466-2147a6191932 dbf4f5a9-b8e0-46a3-9841-9ad71247239e b9bbae2c-2ba6-4cf3-b452-8e8f908696f3 +64b12afc-18b8-4d3f-9eab-7f6cae7c73f9