diff --git a/atomics/T1546.012/T1546.012.yaml b/atomics/T1546.012/T1546.012.yaml index 0c877d11..5ede0615 100644 --- a/atomics/T1546.012/T1546.012.yaml +++ b/atomics/T1546.012/T1546.012.yaml @@ -50,6 +50,7 @@ atomic_tests: name: command_prompt elevation_required: true - name: GlobalFlags in Image File Execution Options + auto_generated_guid: 13117939-c9b2-4a43-999e-0a543df92f0d description: | The following Atomic Test will create a GlobalFlag key under Image File Execution Options, also a SilentProcessExit Key with ReportingMode and MonitorProcess values. This test is similar to a recent CanaryToken that will generate an EventCode 3000 in the Application log when a command, whoami.exe for example, is executed. Upon running Whoami.exe, a command shell will spawn and start calc.exe based on the MonitorProcess value. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 0d002136..f3e3b8de 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1145,3 +1145,4 @@ f450461c-18d1-4452-9f0d-2c42c3f08624 59dbeb1a-79a7-4c2a-baf4-46d0f4c761c4 c2587b8d-743d-4985-aa50-c83394eaeb68 d5d5a6b0-0f92-42d8-985d-47aafa2dd4db +13117939-c9b2-4a43-999e-0a543df92f0d