Théo Letailleur
fff607c240
[FIX] T1047 - fix tightvnc path ( #2636 )
2023-12-13 14:50:54 -06:00
Carrie Roberts
07da073a66
fix command ( #2557 )
2023-10-10 09:55:20 -06:00
Carrie Roberts
d4709021fb
Handle spaces in file paths ( #2535 )
...
* updating atomics count in README.md [ci skip]
* wip
* handle spaces in path
* update readme
* fix typo
---------
Co-authored-by: publish bot <opensource@redcanary.com >
2023-09-22 10:47:25 -06:00
Carrie Roberts
068d32b1ea
use ExternalPayloads directory ( #2460 )
...
* use ExternalPayloads directory
* use ExternalPayloads directory
* use ExternalPayloads directory
2023-06-15 10:16:12 -06:00
KillrBunn3
65294196d0
Spelling adjustments ( #2448 )
...
Looking over the YAMLs mostly, only changes for readability or accuracy
2023-05-31 15:50:22 -05:00
Josh Rickard
a5dd0813cd
fix: Updating atomics YAML file structure to align with the new JSON schema definition ( #2323 )
...
* fix: Updating atomics YAML file structure to align with the new JSON schema definition.
This also fixes some white space issues and general line formatting across all impacted atomics.
* fix: One additional change needed
---------
Co-authored-by: MSAdministrator <MSAdministrator@users.noreply.github.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2023-02-13 16:10:37 -07:00
Kevin2755
3bd6a03d0f
Update PathToAtomicsFolder ( #1742 )
...
* Update to PathToAtomicsFolder
* Put GUID back in
2022-01-25 13:22:44 -07:00
CircleCI Atomic Red Team GUID generator
8ff4585f4c
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-01-25 19:19:31 +00:00
Kevin2755
b2043cdf3e
Application uninstall using WMIC ( #1741 )
2022-01-25 12:19:07 -07:00
Carrie Roberts
5bb5878e62
Cleaning up the Cleanup commands ( #1685 )
...
* cleanup fixes
* cleanup fixes
* cleanup fixes
2021-12-09 11:42:14 -07:00
Raislin
d5c9c01e4f
Update T1047.yaml ( #1624 )
2021-09-09 15:10:08 -06:00
CircleCI Atomic Red Team GUID generator
acd77c68cb
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-09-09 20:59:10 +00:00
Raislin
167fb3c2f6
T1047_update ( #1623 )
...
* T1047_update
* T1047_update
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2021-09-09 14:58:43 -06:00
CircleCI Atomic Red Team GUID generator
5f57e740fb
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-05-13 20:44:10 +00:00
Ján Trenčanský
a7a1e69bda
WMI create process using indirect Win32_Process call ( #1461 )
...
* Win32_Process obfuscate
* T1047-8 cleanup command
* T1047-8 add process_to_execute argument
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2021-05-13 14:43:37 -06:00
CircleCI Atomic Red Team GUID generator
ed7d3faabd
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-01-07 16:43:06 +00:00
Carrie Roberts
6f40ae85f5
solarigate atomic ( #1358 )
2021-01-07 09:42:43 -07:00
cnotin
6000965b1e
T1028 "Windows Remote Management": split in several techniques
...
Fixes #1042
2020-09-18 15:57:11 +02:00
Carrie Roberts
24549e3866
Convert to Mitre ATT&CK sub-technique schema ( #1056 )
...
* Initial transfer of atomics to MITRE subtechniques
* Add GUIDs back in, attack_technique to string (#1019 )
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* Subtechnique transfer T1220-T1546.005 (#1020 )
* Create T1222.001.yaml
* Create T1222.002.yaml
* Create T1505.002.yaml
* Update T1543.003.yaml
* Update AtomicService.cs
* Update T1546.005.yaml
* Delete T1222.yaml
* Update T1482.yaml
* Update T1485.yaml
* Update T1220.yaml
* Update T1489.yaml
* Update T1490.yaml
* Update T1496.yaml
* Update T1505.003.yaml
* Update T1505.yaml
* Update T1518.001.yaml
* Update T1518.yaml
* Update T1529.yaml
* Update T1543.004.yaml
* Update T1546.001.yaml
* Update T1546.002.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.002.yaml
* Update T1543.001.yaml
* Update T1518.001.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1531.yaml
* Update T1222.001.yaml
* Update T1222.002.yaml
* Update T1505.002.yaml
* Update T1505.003.yaml
* Update T1518.001.yaml
* Update T1543.001.yaml
* Update T1546.005.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.003.yaml
* Update T1543.002.yaml
* added auto_generated_guid 1220
* added T1222.001 auto_generated_guid
* Update T1222.002.yaml
added auto_generated_guid entries
* Update T1482.yaml
auto_generated_guid added
* Update T1485.yaml
added auto_generated_guids
* Update T1489.yaml
added auto_generated_guids
* Update T1490.yaml
added auto_generated_guids
* Update T1496.yaml
added auto_generated_guid
* Update T1505.002.yaml
added auto_generated_guid from old T1505 same atomic
* Update T1505.003.yaml
added auto_generated_guid from previous atomic 1100
* Delete T1505.yaml
no longer needed, moved to 1505.002
* Update T1518.yaml
added auto_generated_guids
* Update T1529.yaml
added auto_generated_guids
* Update T1531.yaml
added auto_generated_guids
* Update T1543.001.yaml
added auto_generated_guid
* Update T1543.002.yaml
added auto_generated_guid
* Update T1543.004.yaml
added auto_generated_guid
* Update T1546.001.yaml
added auto_generated_guid
* Update T1546.002.yaml
added auto_generated_guid
* Update T1546.003.yaml
* Update T1546.004.yaml
added auto_generated_guid
* Update T1546.005.yaml
added auto_generated_guid
* add guids back in
* fix spacing issue
* fix spacing
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Sub-techniques T1053-T1113 - Updates (#1022 )
* Sub-techniques T1053-T1113 - Updates
Updated techniques for sub-techniques.
* minor fixes
format fixing
* Added GUIDs
- Added GUIDs back
- Fixed typo (T1054)
- Fixed attack_technique from an array to a string
* Sub-technique updates T1546.008 through T1574.011 (#1024 )
* sub technique updates
* sub technique updates
* sub technique updates
* Carrie updates (#1017 )
* updated T1110,12,13
* updated T1114
* updated T1114
* updated T1115
* updated T1119
* updated T1123,24
* updated T1127
* updated T1114
* updated T1127
* updated T1132
* T1134.004
* T1134.004
* updated T1135
* updated T1136
* updated T1137
* updated T1140
* remove depracted T1153
* updated T1176
* updated T1197
* updated T1201
* updated T1202
* updated T1204
* updated T1207
* updated T1216
* updated T1204
* updated T1217
* updated T1218
* updated T1218
* updated T1219
* updated T1218
* attack_technique to string
* Subtechnique transfer (#1025 )
* T1003 review
* T1005 manual review changes
* T1027.002 sub-technique review
* T1027.004 sub-technique review
* T1036 sub-technique review
* T1037 sub-technique review
* T1048 sub-technique review
* YAML bugfixes
* Adding auto-generated GUIDs back to tests
* merging with Mike's PR
* Merging with Carrie's PR
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Subtechnique fix (#1026 )
* add atomic_tests: element
* add atomic_tests: element
* more fixes
* more fixes
* more fixes
* sub technique minor fixes 1 (#1027 )
* fixes
* fixes
* more fixes
* more fixes
* display name fix (#1028 )
* remove some deprecated stuff. reorganize a little (#1031 )
* Gendocs fix (#1033 )
* gendocs updates for subtechniques
* add folders
* ignore auto generated markdown files
* remove tmp files
* add tmp files
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
* navigator layer v3.0
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
Co-authored-by: Matt Graeber <60448025+mgraeber-rc@users.noreply.github.com >
Co-authored-by: Tsora-Pop <35981510+Tsora-Pop@users.noreply.github.com >
Co-authored-by: Michael Haag <mike@redcanary.com >
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-06-17 12:55:46 -06:00
CircleCI Atomic Red Team doc generator
35c42f2c61
Generate docs from job=validate_atomics_generate_docs branch=master
2020-05-15 17:19:25 +00:00
tlor89
5d41e4168e
T1002-T1049_Cleanup ( #930 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-04-06 17:05:47 -06:00
san-gwea
e42f1f27ab
T1047 documentation ( #896 )
...
* Added descriptions to indicate when the commands works, replaced default host , exe and output format
* removing cleanup test 1,2,3
* fixed platform specific info
* added documentation on test 4
* typo correction
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-03-19 16:15:33 -06:00
Tony M Lambert
8eb281faa6
T1047 - Wmic process create tests ( #679 )
...
* T1047 - Wmic process create tests
* Generate docs from job=validate_atomics_generate_docs branch=t1047-wmic-process
2019-11-20 15:36:42 -07:00
Carrie Roberts
1bfefdacfc
Add elevated ( #542 )
...
* provide elevation_required attribute
* provide elevation_required attribute
* provide elevation_required attribute
2019-09-03 07:34:42 -06:00
caseysmithrc
27a26d584b
T1047
2018-05-23 20:47:53 -06:00