diff --git a/atomics/T1562.001/T1562.001.yaml b/atomics/T1562.001/T1562.001.yaml index dc5ae882..ce11ec3d 100644 --- a/atomics/T1562.001/T1562.001.yaml +++ b/atomics/T1562.001/T1562.001.yaml @@ -955,6 +955,7 @@ atomic_tests: name: sh elevation_required: true - name: Tamper with Windows Defender Registry - Reg.exe + auto_generated_guid: 1f6743da-6ecc-4a93-b03f-dc357e4b313f description: | Disable Windows Defender by tampering with windows defender registry using the utility "reg.exe" supported_platforms: @@ -1001,6 +1002,7 @@ atomic_tests: name: command_prompt elevation_required: true - name: Tamper with Windows Defender Registry - Powershell + auto_generated_guid: a72cfef8-d252-48b3-b292-635d332625c3 description: | Disable Windows Defender by tampering with windows defender registry through powershell supported_platforms: diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 314f5e97..410d90a3 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1499,3 +1499,5 @@ a9030b20-dd4b-4405-875e-3462c6078fdc 505f24be-1c11-4694-b614-e01ae1cd2570 00cbb875-7ae4-4cf1-b638-e543fd825300 0128e48e-8c1a-433a-a11a-a5387384f1e1 +1f6743da-6ecc-4a93-b03f-dc357e4b313f +a72cfef8-d252-48b3-b292-635d332625c3