diff --git a/atomics/T1003.001/T1003.001.yaml b/atomics/T1003.001/T1003.001.yaml index 0c25475b..d29dd83d 100644 --- a/atomics/T1003.001/T1003.001.yaml +++ b/atomics/T1003.001/T1003.001.yaml @@ -140,6 +140,7 @@ atomic_tests: elevation_required: true - name: Dump LSASS.exe Memory using NanoDump + auto_generated_guid: dddd4aca-bbed-46f0-984d-e4c5971c51ea description: | The NanoDump tool uses syscalls and an invalid dump signature to avoid detection. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 61433421..67b6c4df 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -820,3 +820,4 @@ f449c933-0891-407f-821e-7916a21a1a6f 3de33f5b-62e5-4e63-a2a0-6fd8808c80ec d3eda496-1fc0-49e9-aff5-3bec5da9fa22 e42d33cd-205c-4acf-ab59-a9f38f6bad9c +dddd4aca-bbed-46f0-984d-e4c5971c51ea