diff --git a/Mac/Credential_Access/Keychain.md b/Mac/Credential_Access/Keychain.md deleted file mode 100644 index 0af2889b..00000000 --- a/Mac/Credential_Access/Keychain.md +++ /dev/null @@ -1,32 +0,0 @@ -# Keychain - -MITRE ATT&CK Technique: [T1142](https://attack.mitre.org/wiki/Technique/T1142) - -### Keychain Files - - ~/Library/Keychains/ - - /Library/Keychains/ - - /Network/Library/Keychains/ - -### security command line - -Input: - - security -h - -Input: - - security find-certificate -a -p > allcerts.pem - -Input: - - security import /tmp/certs.pem -k - - -### References - -[Security Reference](https://developer.apple.com/legacy/library/documentation/Darwin/Reference/ManPages/man1/security.1.html) - -[Keychain dumper](https://github.com/juuso/keychaindump) diff --git a/atomics/T1142/T1142.yaml b/atomics/T1142/T1142.yaml new file mode 100644 index 00000000..c546e9d6 --- /dev/null +++ b/atomics/T1142/T1142.yaml @@ -0,0 +1,29 @@ +--- +attack_technique: T1142 +display_name: Keychain + +atomic_tests: +- name: Keychain + description: | + ### Keychain Files + + ~/Library/Keychains/ + + /Library/Keychains/ + + /Network/Library/Keychains/ + + [Security Reference](https://developer.apple.com/legacy/library/documentation/Darwin/Reference/ManPages/man1/security.1.html) + + [Keychain dumper](https://github.com/juuso/keychaindump) + + + supported_platforms: + - macos + + executor: + name: sh + command: | + security -h + security find-certificate -a -p > allcerts.pem + security import /tmp/certs.pem -k