From 6bb3c3351dd996d59ea46c616d071ae5aca89a31 Mon Sep 17 00:00:00 2001 From: CircleCI Atomic Red Team doc generator Date: Fri, 19 Jun 2020 22:23:26 +0000 Subject: [PATCH] Generate docs from job=validate_atomics_generate_docs branch=master --- atomics/Indexes/index.yaml | 3 +++ atomics/T1569.002/T1569.002.md | 4 ++++ 2 files changed, 7 insertions(+) diff --git a/atomics/Indexes/index.yaml b/atomics/Indexes/index.yaml index ed3285d3..5793388b 100644 --- a/atomics/Indexes/index.yaml +++ b/atomics/Indexes/index.yaml @@ -40080,6 +40080,9 @@ execution: sc.exe create #{service_name} binPath= "#{executable_command}" sc.exe start #{service_name} sc.exe delete #{service_name} + cleanup_command: 'del C:\art-marker.txt >nul 2>&1 + +' name: command_prompt elevation_required: true - name: Use PsExec to execute a command on a remote host diff --git a/atomics/T1569.002/T1569.002.md b/atomics/T1569.002/T1569.002.md index e9bd772e..4ac4cb86 100644 --- a/atomics/T1569.002/T1569.002.md +++ b/atomics/T1569.002/T1569.002.md @@ -41,6 +41,10 @@ sc.exe start #{service_name} sc.exe delete #{service_name} ``` +#### Cleanup Commands: +```cmd +del C:\art-marker.txt >nul 2>&1 +```