From e935cc7fe58b0c3a608a307b40259f3350cfd0a8 Mon Sep 17 00:00:00 2001 From: Atomic Red Team GUID generator Date: Mon, 25 Jul 2022 20:54:06 +0000 Subject: [PATCH] Generate GUIDs from job=generate-docs branch=master [skip ci] --- atomics/T1569.002/T1569.002.yaml | 1 + atomics/used_guids.txt | 1 + 2 files changed, 2 insertions(+) diff --git a/atomics/T1569.002/T1569.002.yaml b/atomics/T1569.002/T1569.002.yaml index c66189ac..fcaafe21 100644 --- a/atomics/T1569.002/T1569.002.yaml +++ b/atomics/T1569.002/T1569.002.yaml @@ -116,6 +116,7 @@ atomic_tests: psexec.py '#{domain}/#{username}:#{password}@#{remote_host}' '#{command}' name: bash - name: BlackCat pre-encryption cmds with Lateral Movement + auto_generated_guid: 31eb7828-97d7-4067-9c1e-c6feb85edc4b description: This atomic attempts to emulate the unique behavior of BlackCat ransomware prior to encryption and during Lateral Movement attempts via PsExec on Windows. Uses bundled PsExec like BlackCat supported_platforms: - windows diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index fc2d6474..dd594678 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1092,3 +1092,4 @@ c531aa6e-9c97-4b29-afee-9b7be6fc8a64 df81db1b-066c-4802-9bc8-b6d030c3ba8e 29786d7e-8916-4de6-9c55-be7b093b2706 6fdaae87-c05b-42f8-842e-991a74e8376b +31eb7828-97d7-4067-9c1e-c6feb85edc4b