Josh Rickard
a5dd0813cd
fix: Updating atomics YAML file structure to align with the new JSON schema definition ( #2323 )
...
* fix: Updating atomics YAML file structure to align with the new JSON schema definition.
This also fixes some white space issues and general line formatting across all impacted atomics.
* fix: One additional change needed
---------
Co-authored-by: MSAdministrator <MSAdministrator@users.noreply.github.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2023-02-13 16:10:37 -07:00
David McKennirey
6b5a4b333e
Update timeout command to ping ( #1865 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-04-12 20:58:03 -06:00
Carrie Roberts
5bb5878e62
Cleaning up the Cleanup commands ( #1685 )
...
* cleanup fixes
* cleanup fixes
* cleanup fixes
2021-12-09 11:42:14 -07:00
Josh Rickard
1513717eb2
Updating atomics to conform to standard ( #1619 )
...
* Updated format of input_argument types for Url
* Updated type for input_arguments to Url (missed)
* Updating Path type for input_arguments
* Updated String type for input_arguments
* Missed a few Strings and Url types
* Updated default values for input_arguments to align with their types
* Updated Integer type for input_arguments
* Updated formatting and spacing of atomics
2021-09-03 18:20:46 -06:00
Michael Haag
e4f7f67202
Update T1197.yaml ( #1535 )
...
* Update T1197.yaml
Resolving #1459
* Update T1197.yaml
* Update T1197.yaml
2021-06-28 12:28:26 -06:00
Carrie Roberts
1f26ebdb6c
typo corrections ( #1367 )
...
addresses issues #1365
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com >
2021-01-13 12:14:14 -07:00
Rodney
de05b1a73d
Update T1070.003.yaml ( #1283 )
...
* Update T1070.003.yaml
* Update T1078.001.yaml
* Update T1113.yaml
Remove error from screen when cleaning up for T1113-5
* Update T1197.yaml
Remove error when cleaning up for T1197-4
* Update T1562.001.yaml
Remove error from cleanup of T1562.001-23
* Update T1562.004.yaml
Remove error shown for cleanup of T15262.004-5 and T15262.004-6
* Update T1574.009.yaml
Remove error from cleanup of T1574.009-1
* Update T1553.004.yaml
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-11-12 11:29:08 -07:00
Carrie Roberts
1b0994ea9e
update/clarify description ( #1247 )
...
* update/clarify description
* Generate docs from job=validate_atomics_generate_docs branch=clr2of8-patch-10
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-10-08 12:03:40 -06:00
CircleCI Atomic Red Team doc generator
84054abce5
Generate docs from job=validate_atomics_generate_docs branch=master
2020-08-20 20:28:30 +00:00
Brandon Morgan
c8be2137d7
T1197 desktopimgdwnldr.exe ( #1206 )
...
* Update T1197.yaml
desktopimgdownldr.exe initial commit
* Update T1197.yaml
fixed parsing issue with command
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-08-20 14:27:09 -06:00
Clément Notin
e1d1141689
T1197: reorder and fix bitsadmin commands ( #1048 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-29 16:43:29 -06:00
Clément Notin
0376bf02d0
T1197: add cleanup command to test 3 ( #1049 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-19 16:47:44 -06:00
Clément Notin
5258767a8e
T1197: use different names for local files of different tests ( #1050 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-19 16:46:01 -06:00
Carrie Roberts
24549e3866
Convert to Mitre ATT&CK sub-technique schema ( #1056 )
...
* Initial transfer of atomics to MITRE subtechniques
* Add GUIDs back in, attack_technique to string (#1019 )
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* Subtechnique transfer T1220-T1546.005 (#1020 )
* Create T1222.001.yaml
* Create T1222.002.yaml
* Create T1505.002.yaml
* Update T1543.003.yaml
* Update AtomicService.cs
* Update T1546.005.yaml
* Delete T1222.yaml
* Update T1482.yaml
* Update T1485.yaml
* Update T1220.yaml
* Update T1489.yaml
* Update T1490.yaml
* Update T1496.yaml
* Update T1505.003.yaml
* Update T1505.yaml
* Update T1518.001.yaml
* Update T1518.yaml
* Update T1529.yaml
* Update T1543.004.yaml
* Update T1546.001.yaml
* Update T1546.002.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.002.yaml
* Update T1543.001.yaml
* Update T1518.001.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1531.yaml
* Update T1222.001.yaml
* Update T1222.002.yaml
* Update T1505.002.yaml
* Update T1505.003.yaml
* Update T1518.001.yaml
* Update T1543.001.yaml
* Update T1546.005.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.003.yaml
* Update T1543.002.yaml
* added auto_generated_guid 1220
* added T1222.001 auto_generated_guid
* Update T1222.002.yaml
added auto_generated_guid entries
* Update T1482.yaml
auto_generated_guid added
* Update T1485.yaml
added auto_generated_guids
* Update T1489.yaml
added auto_generated_guids
* Update T1490.yaml
added auto_generated_guids
* Update T1496.yaml
added auto_generated_guid
* Update T1505.002.yaml
added auto_generated_guid from old T1505 same atomic
* Update T1505.003.yaml
added auto_generated_guid from previous atomic 1100
* Delete T1505.yaml
no longer needed, moved to 1505.002
* Update T1518.yaml
added auto_generated_guids
* Update T1529.yaml
added auto_generated_guids
* Update T1531.yaml
added auto_generated_guids
* Update T1543.001.yaml
added auto_generated_guid
* Update T1543.002.yaml
added auto_generated_guid
* Update T1543.004.yaml
added auto_generated_guid
* Update T1546.001.yaml
added auto_generated_guid
* Update T1546.002.yaml
added auto_generated_guid
* Update T1546.003.yaml
* Update T1546.004.yaml
added auto_generated_guid
* Update T1546.005.yaml
added auto_generated_guid
* add guids back in
* fix spacing issue
* fix spacing
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Sub-techniques T1053-T1113 - Updates (#1022 )
* Sub-techniques T1053-T1113 - Updates
Updated techniques for sub-techniques.
* minor fixes
format fixing
* Added GUIDs
- Added GUIDs back
- Fixed typo (T1054)
- Fixed attack_technique from an array to a string
* Sub-technique updates T1546.008 through T1574.011 (#1024 )
* sub technique updates
* sub technique updates
* sub technique updates
* Carrie updates (#1017 )
* updated T1110,12,13
* updated T1114
* updated T1114
* updated T1115
* updated T1119
* updated T1123,24
* updated T1127
* updated T1114
* updated T1127
* updated T1132
* T1134.004
* T1134.004
* updated T1135
* updated T1136
* updated T1137
* updated T1140
* remove depracted T1153
* updated T1176
* updated T1197
* updated T1201
* updated T1202
* updated T1204
* updated T1207
* updated T1216
* updated T1204
* updated T1217
* updated T1218
* updated T1218
* updated T1219
* updated T1218
* attack_technique to string
* Subtechnique transfer (#1025 )
* T1003 review
* T1005 manual review changes
* T1027.002 sub-technique review
* T1027.004 sub-technique review
* T1036 sub-technique review
* T1037 sub-technique review
* T1048 sub-technique review
* YAML bugfixes
* Adding auto-generated GUIDs back to tests
* merging with Mike's PR
* Merging with Carrie's PR
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Subtechnique fix (#1026 )
* add atomic_tests: element
* add atomic_tests: element
* more fixes
* more fixes
* more fixes
* sub technique minor fixes 1 (#1027 )
* fixes
* fixes
* more fixes
* more fixes
* display name fix (#1028 )
* remove some deprecated stuff. reorganize a little (#1031 )
* Gendocs fix (#1033 )
* gendocs updates for subtechniques
* add folders
* ignore auto generated markdown files
* remove tmp files
* add tmp files
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
* navigator layer v3.0
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
Co-authored-by: Matt Graeber <60448025+mgraeber-rc@users.noreply.github.com >
Co-authored-by: Tsora-Pop <35981510+Tsora-Pop@users.noreply.github.com >
Co-authored-by: Michael Haag <mike@redcanary.com >
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-06-17 12:55:46 -06:00
CircleCI Atomic Red Team doc generator
35c42f2c61
Generate docs from job=validate_atomics_generate_docs branch=master
2020-05-15 17:19:25 +00:00
Andrew Beers
49e0553d98
Successful execution documentation ( #891 )
...
* start work
* more fixes
2020-03-18 13:10:33 -06:00
JrOrOneEquals1
3fa4dd1c9e
Fixed cleanup commands ( #869 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-03-10 17:06:14 -06:00
Carrie Roberts
0dcde71a15
Asynchronous Attack Execution and other handy things ( #790 )
...
* execute attack in separate process
* install from custom repoOwner and branch
* remove zip after install
* added showdetails brief and sleep for linux output
* remove positional param spec
* replacing special PathToAtomicsFolder in commands
* use pwsh on linux
* kill proc tree linux
* include path in remove-item
* update readme
* update readme
* update readme
Co-authored-by: Tony M Lambert <ForensicITGuy@users.noreply.github.com >
2020-01-22 21:36:20 -06:00
Andrew Beers
4364411ff4
update tests ( #725 )
2019-12-16 17:03:20 -07:00
Michael Haag
820ed2e465
T1197 ( #473 )
...
* Update T1197.yaml
Fixed issue #463
Fixed issue #464
* Generate docs from job=validate_atomics_generate_docs branch=t1197
2019-03-26 13:12:49 -07:00
Tony M Lambert
9a487bd26a
Added test for persistence via BITS ( #409 )
2018-12-04 16:38:19 -08:00
caseysmithrc
7d4f04c153
fixed cmdline test
2018-06-20 11:13:12 -06:00
caseysmithrc
6c3d7c58e8
Fix Link
2018-06-20 11:07:04 -06:00
caseysmithrc
71138a43ac
Fix BitsAdmin Urls
2018-06-20 10:55:02 -06:00
Mo Amiri
df6ed4a300
Formatting
2018-05-31 00:52:47 +01:00
caseysmithrc
bb185cc1d6
yamlize - remove original
2018-05-23 17:45:50 -06:00