From 535c5be594528f4a7df4aeb15b37f6ae0cee1ea4 Mon Sep 17 00:00:00 2001 From: Atomic Red Team GUID generator Date: Mon, 31 Oct 2022 18:55:16 +0000 Subject: [PATCH] Generate GUIDs from job=generate-docs branch=master [skip ci] --- atomics/T1562.001/T1562.001.yaml | 1 + atomics/used_guids.txt | 1 + 2 files changed, 2 insertions(+) diff --git a/atomics/T1562.001/T1562.001.yaml b/atomics/T1562.001/T1562.001.yaml index 01f2207f..75d7fe04 100644 --- a/atomics/T1562.001/T1562.001.yaml +++ b/atomics/T1562.001/T1562.001.yaml @@ -748,6 +748,7 @@ atomic_tests: elevation_required: true - name: WMIC Tamper with Windows Defender Evade Scanning Folder + auto_generated_guid: 59d386fc-3a4b-41b8-850d-9e3eee24dfe4 description: | The following Atomic will attempt to exclude a folder within Defender leveraging WMI Reference: https://www.bleepingcomputer.com/news/security/gootkit-malware-bypasses-windows-defender-by-setting-path-exclusions/ diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 68cd3517..be07e74d 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1169,3 +1169,4 @@ f9b8daff-8fa7-4e6a-a1a7-7c14675a545b 9c10d16b-20b1-403a-8e67-50ef7117ed4e aca9ae16-7425-4b6d-8c30-cad306fdbd5b 30cbeda4-08d9-42f1-8685-197fad677734 +59d386fc-3a4b-41b8-850d-9e3eee24dfe4