Fix T1543.001 Test 2 Defaults (#2338)
Co-authored-by: Nathan McNulty <nathanmcnulty@outlook.com>
This commit is contained in:
@@ -83,8 +83,8 @@ This test adds persistence via a plist to execute via the macOS Event Monitor Da
|
||||
#### Inputs:
|
||||
| Name | Description | Type | Default Value |
|
||||
|------|-------------|------|---------------|
|
||||
| script_location | evil plist location | path | $PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist|
|
||||
| script_destination | Path where to move the evil plist | path | /etc/emond.d/rules/atomicredteam_T1053_004.plist|
|
||||
| script_location | evil plist location | path | $PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist|
|
||||
| script_destination | Path where to move the evil plist | path | /etc/emond.d/rules/atomicredteam_T1543_001.plist|
|
||||
| empty_file | Random name of the empty file used to trigger emond service | string | randomflag|
|
||||
|
||||
|
||||
|
||||
@@ -45,11 +45,11 @@ atomic_tests:
|
||||
script_location:
|
||||
description: evil plist location
|
||||
type: path
|
||||
default: $PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist
|
||||
default: $PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist
|
||||
script_destination:
|
||||
description: Path where to move the evil plist
|
||||
type: path
|
||||
default: /etc/emond.d/rules/atomicredteam_T1053_004.plist
|
||||
default: /etc/emond.d/rules/atomicredteam_T1543_001.plist
|
||||
empty_file:
|
||||
description: Random name of the empty file used to trigger emond service
|
||||
type: string
|
||||
|
||||
Reference in New Issue
Block a user