diff --git a/atomics/T1562.001/T1562.001.yaml b/atomics/T1562.001/T1562.001.yaml index 9f5e9db3..407de5f4 100644 --- a/atomics/T1562.001/T1562.001.yaml +++ b/atomics/T1562.001/T1562.001.yaml @@ -925,6 +925,7 @@ atomic_tests: name: bash elevation_required: false - name: Tamper with Defender ATP on Linux/MacOS + auto_generated_guid: 40074085-dbc8-492b-90a3-11bcfc52fda8 description: | With root privileges, an adversary can disable real time protection. Note, this test assumes Defender is not in passive mode and real-time protection is enabled. The use of a managed.json on Linux or Defender .plist on MacOS will prevent these changes. Tamper protection will also prevent this (available on MacOS, but not Linux at the time of writing). Installation of MDATP is a prerequisite. Installation steps vary across MacOS and Linux distros. See Microsoft public documentation for instructions: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-install-manually?view=o365-worldwide https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-install-manually?view=o365-worldwide supported_platforms: diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index d812d6c9..ca61f8b0 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1409,3 +1409,4 @@ e12f5d8d-574a-4e9d-8a84-c0e8b4a8a675 7f66d539-4fbe-4cfa-9a56-4a2bf660c58a d380c318-0b34-45cb-9dad-828c11891e43 18136e38-0530-49b2-b309-eed173787471 +40074085-dbc8-492b-90a3-11bcfc52fda8