From 50f1ea7a063160ea6fa23b350f2de7d9bdfc4dda Mon Sep 17 00:00:00 2001 From: CircleCI Atomic Red Team GUID generator Date: Fri, 30 Apr 2021 20:50:22 +0000 Subject: [PATCH] Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] --- atomics/T1053.005/T1053.005.yaml | 1 + atomics/used_guids.txt | 1 + 2 files changed, 2 insertions(+) diff --git a/atomics/T1053.005/T1053.005.yaml b/atomics/T1053.005/T1053.005.yaml index 7c078652..a7a51aef 100644 --- a/atomics/T1053.005/T1053.005.yaml +++ b/atomics/T1053.005/T1053.005.yaml @@ -131,6 +131,7 @@ atomic_tests: Invoke-MalDoc -macroFile "PathToAtomicsFolder\T1053.005\src\T1053.005-macrocode.txt" -officeProduct "#{ms_product}" -sub "Scheduler" name: powershell - name: WMI Invoke-CimMethod Scheduled Task + auto_generated_guid: e16b3b75-dc9e-4cde-a23d-dfa2d0507b3b description: | Create an scheduled task that executes notepad.exe after user login from XML by leveraging WMI class PS_ScheduledTask. Does the same thing as Register-ScheduledTask cmdlet behind the scenes. supported_platforms: diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 80490044..6c053da8 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -678,3 +678,4 @@ d34ef297-f178-4462-871e-9ce618d44e50 23b91cd2-c99c-4002-9e41-317c63e024a2 ff1d8c25-2aa4-4f18-a425-fede4a41ee88 30558d53-9d76-41c4-9267-a7bd5184bed36ca45b04-9f15-4424-b9d3-84a217285a5c +e16b3b75-dc9e-4cde-a23d-dfa2d0507b3b