From 7e4f6a4b8860cb537e025c917f26b13d31db1a62 Mon Sep 17 00:00:00 2001 From: CircleCI Atomic Red Team GUID generator Date: Mon, 30 Aug 2021 19:52:38 +0000 Subject: [PATCH] Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] --- atomics/T1553.005/T1553.005.yaml | 1 + atomics/used_guids.txt | 1 + 2 files changed, 2 insertions(+) diff --git a/atomics/T1553.005/T1553.005.yaml b/atomics/T1553.005/T1553.005.yaml index 0f1a8003..58ca514d 100644 --- a/atomics/T1553.005/T1553.005.yaml +++ b/atomics/T1553.005/T1553.005.yaml @@ -61,6 +61,7 @@ atomic_tests: name: powershell - name: Remove the Zone.Identifier alternate data stream + auto_generated_guid: 64b12afc-18b8-4d3f-9eab-7f6cae7c73f9 description: | Remove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet. Removing this allows more freedom in executing scripts in PowerShell and avoids opening files in protected view. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 93edac9d..47319e8f 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -781,3 +781,4 @@ bc071188-459f-44d5-901a-f8f2625b2d2e d1253f6e-c29b-49dc-b466-2147a6191932 dbf4f5a9-b8e0-46a3-9841-9ad71247239e b9bbae2c-2ba6-4cf3-b452-8e8f908696f3 +64b12afc-18b8-4d3f-9eab-7f6cae7c73f9