diff --git a/atomics/T1555.003/T1555.003.yaml b/atomics/T1555.003/T1555.003.yaml index ab1ab666..ec85b06c 100644 --- a/atomics/T1555.003/T1555.003.yaml +++ b/atomics/T1555.003/T1555.003.yaml @@ -23,6 +23,7 @@ atomic_tests: prereq_command: | if (Test-Path #{file_path}\SysInternals) {exit 0} else {exit 1} get_prereq_command: | + [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 Invoke-WebRequest "https://github.com/mitre-attack/attack-arsenal/raw/66650cebd33b9a1e180f7b31261da1789cdceb66/adversary_emulation/APT29/CALDERA_DIY/evals/payloads/Modified-SysInternalsSuite.zip" -OutFile "#{file_path}\Modified-SysInternalsSuite.zip" Expand-Archive #{file_path}\Modified-SysInternalsSuite.zip #{file_path}\sysinternals -Force Remove-Item #{file_path}\Modified-SysInternalsSuite.zip -Force @@ -49,4 +50,4 @@ atomic_tests: command: | cd ~/Library/Cookies grep -q "#{search_string}" "Cookies.binarycookies" - name: sh \ No newline at end of file + name: sh