diff --git a/atomics/T1027.007/bin/ninja_syscall1.exe b/atomics/T1027.007/bin/ninja_syscall1.exe deleted file mode 100644 index 1089d358..00000000 Binary files a/atomics/T1027.007/bin/ninja_syscall1.exe and /dev/null differ diff --git a/atomics/T1036.003/bin/T1036.003.exe b/atomics/T1036.003/bin/T1036.003.exe deleted file mode 100644 index eb67343c..00000000 Binary files a/atomics/T1036.003/bin/T1036.003.exe and /dev/null differ diff --git a/atomics/T1036/bin/T1036.zip b/atomics/T1036/bin/T1036.zip deleted file mode 100644 index 878c01bf..00000000 Binary files a/atomics/T1036/bin/T1036.zip and /dev/null differ diff --git a/atomics/T1047/bin/calc.dll b/atomics/T1047/bin/calc.dll deleted file mode 100644 index b3a8095e..00000000 Binary files a/atomics/T1047/bin/calc.dll and /dev/null differ diff --git a/atomics/T1055.002/bin/RedInjection.exe b/atomics/T1055.002/bin/RedInjection.exe deleted file mode 100644 index 5ca6d402..00000000 Binary files a/atomics/T1055.002/bin/RedInjection.exe and /dev/null differ diff --git a/atomics/T1055.003/bin/InjectContext.exe b/atomics/T1055.003/bin/InjectContext.exe deleted file mode 100644 index 2a13906c..00000000 Binary files a/atomics/T1055.003/bin/InjectContext.exe and /dev/null differ diff --git a/atomics/T1055.004/bin/T1055.exe b/atomics/T1055.004/bin/T1055.exe deleted file mode 100755 index 45cbf995..00000000 Binary files a/atomics/T1055.004/bin/T1055.exe and /dev/null differ diff --git a/atomics/T1055.004/bin/x64/EarlyBird.exe b/atomics/T1055.004/bin/x64/EarlyBird.exe deleted file mode 100644 index 3c8f3576..00000000 Binary files a/atomics/T1055.004/bin/x64/EarlyBird.exe and /dev/null differ diff --git a/atomics/T1055.004/bin/x64/NtQueueApcThreadEx.exe b/atomics/T1055.004/bin/x64/NtQueueApcThreadEx.exe deleted file mode 100644 index 3c7c7512..00000000 Binary files a/atomics/T1055.004/bin/x64/NtQueueApcThreadEx.exe and /dev/null differ diff --git a/atomics/T1055.011/bin/T1055.011_x64.exe b/atomics/T1055.011/bin/T1055.011_x64.exe deleted file mode 100644 index 6f5be303..00000000 Binary files a/atomics/T1055.011/bin/T1055.011_x64.exe and /dev/null differ diff --git a/atomics/T1055.011/bin/T1055.011_x86.exe b/atomics/T1055.011/bin/T1055.011_x86.exe deleted file mode 100644 index 7a5d4e38..00000000 Binary files a/atomics/T1055.011/bin/T1055.011_x86.exe and /dev/null differ diff --git a/atomics/T1055.012/bin/x64/CreateProcess.exe b/atomics/T1055.012/bin/x64/CreateProcess.exe deleted file mode 100644 index b2573aaf..00000000 Binary files a/atomics/T1055.012/bin/x64/CreateProcess.exe and /dev/null differ diff --git a/atomics/T1055.012/bin/x64/CreateProcessWithPipe.exe b/atomics/T1055.012/bin/x64/CreateProcessWithPipe.exe deleted file mode 100644 index 4d0a173a..00000000 Binary files a/atomics/T1055.012/bin/x64/CreateProcessWithPipe.exe and /dev/null differ diff --git a/atomics/T1055.015/bin/listPlanting.exe b/atomics/T1055.015/bin/listPlanting.exe deleted file mode 100644 index 6fc63edc..00000000 Binary files a/atomics/T1055.015/bin/listPlanting.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/CreateRemoteThread.exe b/atomics/T1055/bin/x64/CreateRemoteThread.exe deleted file mode 100644 index 0b84d2d3..00000000 Binary files a/atomics/T1055/bin/x64/CreateRemoteThread.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/CreateRemoteThreadNative.exe b/atomics/T1055/bin/x64/CreateRemoteThreadNative.exe deleted file mode 100644 index bb038d20..00000000 Binary files a/atomics/T1055/bin/x64/CreateRemoteThreadNative.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/CreateThread.exe b/atomics/T1055/bin/x64/CreateThread.exe deleted file mode 100644 index c346baf2..00000000 Binary files a/atomics/T1055/bin/x64/CreateThread.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/CreateThreadNative.exe b/atomics/T1055/bin/x64/CreateThreadNative.exe deleted file mode 100644 index 6285a13f..00000000 Binary files a/atomics/T1055/bin/x64/CreateThreadNative.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/EtwpCreateEtwThread.exe b/atomics/T1055/bin/x64/EtwpCreateEtwThread.exe deleted file mode 100644 index fbbf6ba9..00000000 Binary files a/atomics/T1055/bin/x64/EtwpCreateEtwThread.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/InjectView.exe b/atomics/T1055/bin/x64/InjectView.exe deleted file mode 100644 index e8898a6b..00000000 Binary files a/atomics/T1055/bin/x64/InjectView.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/RWXinjectionLocal.exe b/atomics/T1055/bin/x64/RWXinjectionLocal.exe deleted file mode 100644 index 27cc61df..00000000 Binary files a/atomics/T1055/bin/x64/RWXinjectionLocal.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/RtlCreateUserThread.exe b/atomics/T1055/bin/x64/RtlCreateUserThread.exe deleted file mode 100644 index aa1787ec..00000000 Binary files a/atomics/T1055/bin/x64/RtlCreateUserThread.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/UuidFromStringA.exe b/atomics/T1055/bin/x64/UuidFromStringA.exe deleted file mode 100644 index 9d59f32b..00000000 Binary files a/atomics/T1055/bin/x64/UuidFromStringA.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/redVanity.exe b/atomics/T1055/bin/x64/redVanity.exe deleted file mode 100644 index 359035a8..00000000 Binary files a/atomics/T1055/bin/x64/redVanity.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/searchVuln.exe b/atomics/T1055/bin/x64/searchVuln.exe deleted file mode 100644 index c370eae4..00000000 Binary files a/atomics/T1055/bin/x64/searchVuln.exe and /dev/null differ diff --git a/atomics/T1055/bin/x64/uuid_injection.exe b/atomics/T1055/bin/x64/uuid_injection.exe deleted file mode 100644 index dc4e3578..00000000 Binary files a/atomics/T1055/bin/x64/uuid_injection.exe and /dev/null differ diff --git a/atomics/T1059.001/bin/SOAPHound.exe b/atomics/T1059.001/bin/SOAPHound.exe deleted file mode 100644 index 7c84163f..00000000 Binary files a/atomics/T1059.001/bin/SOAPHound.exe and /dev/null differ diff --git a/atomics/T1087.002/bin/AdFind.exe b/atomics/T1087.002/bin/AdFind.exe deleted file mode 100644 index 1cfe1c99..00000000 Binary files a/atomics/T1087.002/bin/AdFind.exe and /dev/null differ diff --git a/atomics/T1106/bin/x64/Syscall.exe b/atomics/T1106/bin/x64/Syscall.exe deleted file mode 100644 index 5de60590..00000000 Binary files a/atomics/T1106/bin/x64/Syscall.exe and /dev/null differ diff --git a/atomics/T1134.001/bin/BadPotato.exe b/atomics/T1134.001/bin/BadPotato.exe deleted file mode 100644 index 399c3da6..00000000 Binary files a/atomics/T1134.001/bin/BadPotato.exe and /dev/null differ diff --git a/atomics/T1137.006/bin/Addins/excelxll_x64.xll b/atomics/T1137.006/bin/Addins/excelxll_x64.xll deleted file mode 100644 index 32a2c1cd..00000000 Binary files a/atomics/T1137.006/bin/Addins/excelxll_x64.xll and /dev/null differ diff --git a/atomics/T1137.006/bin/Addins/excelxll_x86.xll b/atomics/T1137.006/bin/Addins/excelxll_x86.xll deleted file mode 100644 index d4f39bcb..00000000 Binary files a/atomics/T1137.006/bin/Addins/excelxll_x86.xll and /dev/null differ diff --git a/atomics/T1137.006/bin/HelloWorldXll.xll b/atomics/T1137.006/bin/HelloWorldXll.xll deleted file mode 100644 index 95d85d81..00000000 Binary files a/atomics/T1137.006/bin/HelloWorldXll.xll and /dev/null differ diff --git a/atomics/T1195.002/T1195.002.yaml b/atomics/T1195.002/T1195.002.yaml index 24a0cd63..004d0adb 100644 --- a/atomics/T1195.002/T1195.002.yaml +++ b/atomics/T1195.002/T1195.002.yaml @@ -3,9 +3,7 @@ display_name: Compromise Software Supply Chain atomic_tests: - name: Simulate npm package installation on a Linux system description: | - Launches a Node.js pod, builds a local npm package whose "install" script writes a marker file (/tmp/malicious), - packs that package, then installs it to simulate a compromised npm package that executes during install. - The pod is automatically deleted after execution and the command prints the marker's contents so detections can be validated. + Launches a short‑lived Kubernetes pod using the Node 18 image, initializes a minimal npm project in /tmp/test, and installs the specified npm package without audit/fund/package‑lock options, simulating potentially suspicious package retrieval (e.g., typosquatting/dependency confusion) from within a container. The pod is deleted after execution. supported_platforms: - containers - linux @@ -26,9 +24,4 @@ atomic_tests: name: bash elevation_required: false command: | - kubectl run #{pod_name} --image=node:18 --restart=Never --attach --rm -i -- bash -lc "mkdir /tmp/test && cd /tmp/test && npm init -y >/dev/null 2>&1 && npm install #{package_name} --no-audit --no-fund --no-package-lock" - - - - - + kubectl run #{pod_name} --image=node:18 --restart=Never --attach --rm -i -- bash -lc "mkdir /tmp/test && cd /tmp/test && npm init -y >/dev/null 2>&1 && npm install #{package_name} --no-audit --no-fund --no-package-lock" \ No newline at end of file diff --git a/atomics/T1204.002/bin/mirrorblast_emulation.xlsm b/atomics/T1204.002/bin/mirrorblast_emulation.xlsm deleted file mode 100644 index dc76be04..00000000 Binary files a/atomics/T1204.002/bin/mirrorblast_emulation.xlsm and /dev/null differ diff --git a/atomics/T1204.002/bin/test10.lnk b/atomics/T1204.002/bin/test10.lnk deleted file mode 100644 index 6fa2e1ec..00000000 Binary files a/atomics/T1204.002/bin/test10.lnk and /dev/null differ diff --git a/atomics/T1218.002/bin/calc.cpl b/atomics/T1218.002/bin/calc.cpl deleted file mode 100644 index d95bbad8..00000000 Binary files a/atomics/T1218.002/bin/calc.cpl and /dev/null differ diff --git a/atomics/T1218.008/bin/o.dll b/atomics/T1218.008/bin/o.dll deleted file mode 100644 index 8b9d1a01..00000000 Binary files a/atomics/T1218.008/bin/o.dll and /dev/null differ diff --git a/atomics/T1218.010/bin/AllTheThingsx64.dll b/atomics/T1218.010/bin/AllTheThingsx64.dll deleted file mode 100644 index 104da81b..00000000 Binary files a/atomics/T1218.010/bin/AllTheThingsx64.dll and /dev/null differ diff --git a/atomics/T1218.010/bin/AllTheThingsx86.dll b/atomics/T1218.010/bin/AllTheThingsx86.dll deleted file mode 100644 index f6764f3c..00000000 Binary files a/atomics/T1218.010/bin/AllTheThingsx86.dll and /dev/null differ diff --git a/atomics/T1218.011/bin/_WT.init b/atomics/T1218.011/bin/_WT.init deleted file mode 100644 index 19114b69..00000000 Binary files a/atomics/T1218.011/bin/_WT.init and /dev/null differ diff --git a/atomics/T1218/bin/calc.dll b/atomics/T1218/bin/calc.dll deleted file mode 100644 index b3a8095e..00000000 Binary files a/atomics/T1218/bin/calc.dll and /dev/null differ diff --git a/atomics/T1546.015/bin/T1546.015_calc.dll b/atomics/T1546.015/bin/T1546.015_calc.dll deleted file mode 100644 index b3a8095e..00000000 Binary files a/atomics/T1546.015/bin/T1546.015_calc.dll and /dev/null differ diff --git a/atomics/T1546/bin/AltWinSock2DLL.dll b/atomics/T1546/bin/AltWinSock2DLL.dll deleted file mode 100644 index 7f4b2d7f..00000000 Binary files a/atomics/T1546/bin/AltWinSock2DLL.dll and /dev/null differ diff --git a/atomics/T1547.003/bin/AtomicTest.dll b/atomics/T1547.003/bin/AtomicTest.dll deleted file mode 100644 index a767202b..00000000 Binary files a/atomics/T1547.003/bin/AtomicTest.dll and /dev/null differ diff --git a/atomics/T1548.002/bin/uacme.zip b/atomics/T1548.002/bin/uacme.zip deleted file mode 100644 index 5c518af8..00000000 Binary files a/atomics/T1548.002/bin/uacme.zip and /dev/null differ diff --git a/atomics/T1553.005/bin/AllTheThings.iso b/atomics/T1553.005/bin/AllTheThings.iso deleted file mode 100644 index d71a30f4..00000000 Binary files a/atomics/T1553.005/bin/AllTheThings.iso and /dev/null differ diff --git a/atomics/T1555.003/bin/WebBrowserPassView.exe b/atomics/T1555.003/bin/WebBrowserPassView.exe deleted file mode 100644 index 628474f2..00000000 Binary files a/atomics/T1555.003/bin/WebBrowserPassView.exe and /dev/null differ diff --git a/atomics/T1559.002/bin/DDE_Document.docx b/atomics/T1559.002/bin/DDE_Document.docx deleted file mode 100644 index f80709f5..00000000 Binary files a/atomics/T1559.002/bin/DDE_Document.docx and /dev/null differ diff --git a/atomics/T1562.002/bin/phant0m.exe b/atomics/T1562.002/bin/phant0m.exe deleted file mode 100644 index cd77cf2b..00000000 Binary files a/atomics/T1562.002/bin/phant0m.exe and /dev/null differ diff --git a/atomics/T1566.001/bin/PhishingAttachment.xlsm b/atomics/T1566.001/bin/PhishingAttachment.xlsm deleted file mode 100644 index 9cbfd3f7..00000000 Binary files a/atomics/T1566.001/bin/PhishingAttachment.xlsm and /dev/null differ diff --git a/atomics/T1574.001/bin/libcurl.dll b/atomics/T1574.001/bin/libcurl.dll deleted file mode 100644 index b608b676..00000000 Binary files a/atomics/T1574.001/bin/libcurl.dll and /dev/null differ