diff --git a/atomics/T1134.005/T1134.005.yaml b/atomics/T1134.005/T1134.005.yaml index f5d7a4f0..0e3b007f 100644 --- a/atomics/T1134.005/T1134.005.yaml +++ b/atomics/T1134.005/T1134.005.yaml @@ -2,6 +2,7 @@ attack_technique: T1134.005 display_name: 'Access Token Manipulation: SID-History Injection' atomic_tests: - name: Injection SID-History with mimikatz + auto_generated_guid: 6bef32e5-9456-4072-8f14-35566fb85401 description: | Adversaries may use SID-History Injection to escalate privileges and bypass access controls. Must be run on domain controller supported_platforms: diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index c87db196..d5520339 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -976,3 +976,4 @@ fbff3f1f-b0bf-448e-840f-7e1687affdce 19c07a45-452d-4620-90ed-4c34fffbe758 26a6b840-4943-4965-8df5-ef1f9a282440 d5b886d9-d1c7-4b6e-a7b0-460041bf2823 +6bef32e5-9456-4072-8f14-35566fb85401