diff --git a/atomics/T1654/T1654.yaml b/atomics/T1654/T1654.yaml index 631ed263..6d4165f7 100644 --- a/atomics/T1654/T1654.yaml +++ b/atomics/T1654/T1654.yaml @@ -2,6 +2,7 @@ attack_technique: T1654 display_name: "Log Enumeration" atomic_tests: - name: Get-EventLog To Enumerate Windows Security Log + auto_generated_guid: a9030b20-dd4b-4405-875e-3462c6078fdc description: |- Uses the built-in PowerShell commandlet Get-EventLog to search for 'SYSTEM' keyword and saves results to a text file. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index f63d68fa..929f6480 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1494,3 +1494,4 @@ f7308845-6da8-468e-99f2-4271f2f5bb67 8b23cae1-66c1-41c5-b79d-e095b6098b5b cedaf7e7-28ee-42ab-ba13-456abd35d1bd 6b8ca3ab-5980-4321-80c3-bcd77c8daed8 +a9030b20-dd4b-4405-875e-3462c6078fdc