diff --git a/atomics/T1218.008/T1218.008.yaml b/atomics/T1218.008/T1218.008.yaml index 4d44ba20..662ff057 100644 --- a/atomics/T1218.008/T1218.008.yaml +++ b/atomics/T1218.008/T1218.008.yaml @@ -26,6 +26,7 @@ atomic_tests: odbcconf.exe /S /A {REGSVR "#{dll_payload}"} name: command_prompt - name: Odbcconf.exe - Load Response File + auto_generated_guid: 331ce274-f9c9-440b-9f8c-a1006e1fce0b description: | Execute arbitrary response file that will spawn PowerShell.exe. Source files: https://github.com/woanware/application-restriction-bypasses diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index bb85bf27..34f87a9a 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1079,3 +1079,4 @@ ecca999b-e0c8-40e8-8416-ad320b146a75 65704cd4-6e36-4b90-b6c1-dc29a82c8e56 c375558d-7c25-45e9-bd64-7b23a97c1db0 3448824b-3c35-4a9e-a8f5-f887f68bea21 +331ce274-f9c9-440b-9f8c-a1006e1fce0b