Update T1037.yaml (#592)
* Adding T1086 Alternate Data Stream atomic * Added newline T1086 * Syncing changes with updstream and origin. * Added Cleanup to Logon Scripts Atomic T1037 * Added timout to allow time for detection logic to register change. * Fixed issue with upstream sync, Re-added timout to allow time for detection logic. * Fixed cleanup command. Yaml tag not working to allow it to run. * Update T1158 test 11. Corrected ADS syntax. Added loop to run embedded ADS command from shell. Also added cleanup code. * Update T1037.yaml Moved Reg delete command under the cleanup_command tag for consistency. * Update T1037.yaml Moved reg removal command under cleanup_command tag for consistency.
This commit is contained in:
@@ -21,7 +21,7 @@ atomic_tests:
|
||||
elevation_required: false
|
||||
command: |
|
||||
REG.exe ADD HKCU\Environment /v UserInitMprLogonScript /t REG_MULTI_SZ /d "#{script_command}"
|
||||
REM cleanup command below.
|
||||
cleanup_command: |
|
||||
REG.exe DELETE HKCU\Environment /v UserInitMprLogonScript /f
|
||||
|
||||
- name: Logon Scripts - Mac
|
||||
|
||||
Reference in New Issue
Block a user