diff --git a/atomics/Indexes/index.yaml b/atomics/Indexes/index.yaml index 8716915c..f6eed336 100644 --- a/atomics/Indexes/index.yaml +++ b/atomics/Indexes/index.yaml @@ -40078,11 +40078,11 @@ privilege-escalation: script_location: description: evil plist location type: path - default: "$PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist" + default: "$PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist" script_destination: description: Path where to move the evil plist type: path - default: "/etc/emond.d/rules/atomicredteam_T1053_004.plist" + default: "/etc/emond.d/rules/atomicredteam_T1543_001.plist" empty_file: description: Random name of the empty file used to trigger emond service type: string @@ -63920,11 +63920,11 @@ persistence: script_location: description: evil plist location type: path - default: "$PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist" + default: "$PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist" script_destination: description: Path where to move the evil plist type: path - default: "/etc/emond.d/rules/atomicredteam_T1053_004.plist" + default: "/etc/emond.d/rules/atomicredteam_T1543_001.plist" empty_file: description: Random name of the empty file used to trigger emond service type: string diff --git a/atomics/Indexes/macos-index.yaml b/atomics/Indexes/macos-index.yaml index 5542f33d..a834871d 100644 --- a/atomics/Indexes/macos-index.yaml +++ b/atomics/Indexes/macos-index.yaml @@ -25215,11 +25215,11 @@ privilege-escalation: script_location: description: evil plist location type: path - default: "$PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist" + default: "$PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist" script_destination: description: Path where to move the evil plist type: path - default: "/etc/emond.d/rules/atomicredteam_T1053_004.plist" + default: "/etc/emond.d/rules/atomicredteam_T1543_001.plist" empty_file: description: Random name of the empty file used to trigger emond service type: string @@ -41310,11 +41310,11 @@ persistence: script_location: description: evil plist location type: path - default: "$PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist" + default: "$PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist" script_destination: description: Path where to move the evil plist type: path - default: "/etc/emond.d/rules/atomicredteam_T1053_004.plist" + default: "/etc/emond.d/rules/atomicredteam_T1543_001.plist" empty_file: description: Random name of the empty file used to trigger emond service type: string diff --git a/atomics/T1543.001/T1543.001.md b/atomics/T1543.001/T1543.001.md index a8563591..92b45534 100644 --- a/atomics/T1543.001/T1543.001.md +++ b/atomics/T1543.001/T1543.001.md @@ -83,8 +83,8 @@ This test adds persistence via a plist to execute via the macOS Event Monitor Da #### Inputs: | Name | Description | Type | Default Value | |------|-------------|------|---------------| -| script_location | evil plist location | path | $PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist| -| script_destination | Path where to move the evil plist | path | /etc/emond.d/rules/atomicredteam_T1053_004.plist| +| script_location | evil plist location | path | $PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist| +| script_destination | Path where to move the evil plist | path | /etc/emond.d/rules/atomicredteam_T1543_001.plist| | empty_file | Random name of the empty file used to trigger emond service | string | randomflag| diff --git a/atomics/T1543.001/T1543.001.yaml b/atomics/T1543.001/T1543.001.yaml index 3ada90e1..4f4c8b8c 100644 --- a/atomics/T1543.001/T1543.001.yaml +++ b/atomics/T1543.001/T1543.001.yaml @@ -45,11 +45,11 @@ atomic_tests: script_location: description: evil plist location type: path - default: $PathToAtomicsFolder/T1053.004/src/atomicredteam_T1053_004.plist + default: $PathToAtomicsFolder/T1543.001/src/atomicredteam_T1543_001.plist script_destination: description: Path where to move the evil plist type: path - default: /etc/emond.d/rules/atomicredteam_T1053_004.plist + default: /etc/emond.d/rules/atomicredteam_T1543_001.plist empty_file: description: Random name of the empty file used to trigger emond service type: string