diff --git a/atomics/T1027/T1027.yaml b/atomics/T1027/T1027.yaml index ae5cb87e..4ba4abdf 100644 --- a/atomics/T1027/T1027.yaml +++ b/atomics/T1027/T1027.yaml @@ -217,6 +217,7 @@ atomic_tests: name: powershell elevation_required: true - name: Execution from Compressed JScript File + auto_generated_guid: fad04df1-5229-4185-b016-fb6010cd87ac description: | Mimic execution of compressed JavaScript file. When successfully executed, calculator.exe will open. This test is meant to help emulate Gootloader as per https://redcanary.com/blog/gootloader/ supported_platforms: diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 59c68a89..1b4b8bab 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1346,3 +1346,4 @@ b299c120-44a7-4d68-b8e2-8ba5a28511ec ffbcfd62-15d6-4989-a21a-80bfc8e58bb5 abf00f6c-9983-4d9a-afbc-6b1c6c6448e1 51a98f96-0269-4e09-a10f-e307779a8b05 +fad04df1-5229-4185-b016-fb6010cd87ac