diff --git a/atomics/T1562.002/T1562.002.yaml b/atomics/T1562.002/T1562.002.yaml index bd006f32..c62376f4 100644 --- a/atomics/T1562.002/T1562.002.yaml +++ b/atomics/T1562.002/T1562.002.yaml @@ -41,6 +41,7 @@ atomic_tests: name: powershell elevation_required: true - name: 'Impair Windows Audit Log Policy' + auto_generated_guid: 5102a3a7-e2d7-4129-9e45-f483f2e0eea8 description: >- Disables the windows audit policy to prevent key host based telemetry being written into the event logs. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index b7d3c91a..55a0bcae 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -656,3 +656,4 @@ ec3a835e-adca-4c7c-88d2-853b69c11bb9 ab042179-c0c5-402f-9bc8-42741f5ce359 584331dd-75bc-4c02-9e0b-17f5fd81c748 7cede33f-0acd-44ef-9774-15511300b24b +5102a3a7-e2d7-4129-9e45-f483f2e0eea8