Atomic Red Team doc generator
07affd5c64
Generated docs from job=generate-docs branch=master [ci skip]
2025-10-01 19:41:26 +00:00
Casey Hennings
eabf4e722d
T1546.008 - Atomic Test Proposal ( #3183 )
...
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-10-01 12:40:19 -07:00
Atomic Red Team doc generator
77ef76acf3
Generated docs from job=generate-docs branch=master [ci skip]
2025-08-12 01:06:10 +00:00
Casey Hennings
c1705f86e3
Update T1546.008.yaml ( #3136 )
...
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-08-11 18:05:08 -07:00
Atomic Red Team doc generator
cdf93972cd
Generated docs from job=generate-docs branch=master [ci skip]
2025-04-06 15:08:56 +00:00
Casey Hennings
6f4a67633c
Update T1546.008.yaml - New Atomic Tests ( #3096 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2025-04-06 10:07:58 -05:00
Atomic Red Team doc generator
098b33bfe2
Generated docs from job=generate-docs branch=master [ci skip]
2025-03-20 00:48:28 +00:00
Casey Hennings
6192857491
Update T1546.008.yaml - New Atomic Test ( #3084 )
...
Co-authored-by: Hare Sudhan <code@0x6c.dev >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2025-03-19 19:47:29 -05:00
Atomic Red Team doc generator
5ede8f21e4
Generated docs from job=generate-docs branch=master [ci skip]
2025-02-13 22:03:40 +00:00
Atomic Red Team doc generator
bee5a4c48f
Generated docs from job=generate-docs branch=master [ci skip]
2024-07-24 14:41:19 +00:00
abhijose09
af560d5067
Update T1546.008.yaml ( #2878 )
...
New Test Added : Auto-start application on user logon
Existing Test Atbroker.exe (AT) Executes Arbitrary Command via Registry Key added modified for addition of elevated privileges to carry out the required testing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2024-07-24 09:40:14 -05:00
Atomic Red Team doc generator
f6fc008a05
Generated docs from job=generate-docs branch=master [ci skip]
2024-01-20 04:21:06 +00:00
Zeta
871b418282
Update T1218.yaml ( #2646 )
...
* Update T1218.yaml
add new test "Atbroker.exe (AT) Executes Arbitrary Command via Registry Key"
* Update T1218.yaml
Move to T1546.008
* Update T1546.008.yaml Details: Add new test - Atbroker.exe (AT) Executes Arbitrary Command via Registry Key
Add new test "Atbroker.exe (AT) Executes Arbitrary Command via Registry Key"
* updating atomics count in README.md [ci skip]
---------
Co-authored-by: publish bot <opensource@redcanary.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2024-01-19 22:14:16 -06:00
Atomic Red Team doc generator
16594d72c5
Generated docs from job=generate-docs branch=master [ci skip]
2023-02-13 23:11:19 +00:00
Josh Rickard
a5dd0813cd
fix: Updating atomics YAML file structure to align with the new JSON schema definition ( #2323 )
...
* fix: Updating atomics YAML file structure to align with the new JSON schema definition.
This also fixes some white space issues and general line formatting across all impacted atomics.
* fix: One additional change needed
---------
Co-authored-by: MSAdministrator <MSAdministrator@users.noreply.github.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2023-02-13 16:10:37 -07:00
Atomic Red Team doc generator
a7e555c092
Generated docs from job=generate-docs branch=master [ci skip]
2023-02-06 20:20:38 +00:00
Atomic Red Team doc generator
a052ee3bca
Generated docs from job=generate-docs branch=master [ci skip]
2022-11-02 17:55:09 +00:00
Atomic Red Team GUID generator
71b8056ed2
Generate GUIDs from job=generate-docs branch=master [skip ci]
2022-11-02 17:55:02 +00:00
Carrie Roberts
8300ec7632
Create Symbolic Link From osk.exe to cmd.exe ( #2218 )
...
* Create Symbolic Link From osk.exe to cmd.exe
* Update T1546.008.yaml
2022-11-02 11:54:33 -06:00
Atomic Red Team doc generator
d0dad62dbc
Generated docs from job=generate-docs branch=master [ci skip]
2022-09-23 22:57:18 +00:00
Atomic Red Team doc generator
9d4e9a9ccd
Generated docs from job=generate-docs branch=master [ci skip]
2022-09-12 17:55:09 +00:00
Carrie Roberts
77ef512930
restoring deleted file ( #2135 )
2022-09-12 11:54:28 -06:00
Michael Haag
5067af0634
Added new T1546.012 ( #2134 )
...
* Update T1546.008.yaml
- https://blog.thinkst.com/2022/09/sensitive-command-token-so-much-offense.html
- https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/registry-entries-for-silent-process-exit
* Update T1546.012.yaml
Added the same test but written in PowerShell.
* Delete T1546.008.yaml
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-09-09 14:26:40 -06:00
CircleCI Atomic Red Team doc generator
36d49de4c8
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 17:04:33 +00:00
CircleCI Atomic Red Team doc generator
575b36a8e6
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 15:16:54 +00:00
Matt Graeber
e9cb3c2f59
Update README.md ( #1302 )
...
* Update README.md
Updating execution frameworks link.
* Generate docs from job=validate_atomics_generate_docs branch=mgraeber-rc-patch-1
* Generate docs from job=validate_atomics_generate_docs branch=mgraeber-rc-patch-1
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
Co-authored-by: Michael Haag <mike@redcanary.com >
2020-11-30 09:18:32 -07:00
P4T12ICK
91ea164b8e
new atomic ( #1298 )
...
Co-authored-by: P4T12ICK <pbareib@splunk.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-11-27 14:13:05 -07:00
CircleCI Atomic Red Team doc generator
910a2a764a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-09-29 13:53:28 +00:00
Michael Haag
2cc5348312
Fix T1551 to T1070 ( #1161 )
...
* Fix T1551 to T1070
Found that we had T1070 labeled incorrectly as T1551. MITRE pushed a fix for this per https://attack.mitre.org/resources/updates/updates-july-2020/
```
Indicator Removal on Host Was incorrectly re-IDd to T1551, restored to T1070 and its sub-techniques were changed to T1070.001, T1070.002, T1070.003, T1070.004, T1070.005, and T1070.006
```
* Generate MD fix
Attempting to get the MD to generate
* Update enterprise-attack.json
* Generate docs from job=validate_atomics_generate_docs branch=T1070-indicator-removal-fix
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-08-01 09:46:06 -06:00
CircleCI Atomic Red Team doc generator
9cdb1bd100
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-26 15:26:33 +00:00
Clément Notin
dbf6e1af6e
T1546.008: re-add cleanup command lost during transition to subtechnique ( #1087 )
...
And improve it
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-26 09:26:01 -06:00
CircleCI Atomic Red Team doc generator
8a82e9b66a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-18 01:57:35 +00:00
Carrie Roberts
24549e3866
Convert to Mitre ATT&CK sub-technique schema ( #1056 )
...
* Initial transfer of atomics to MITRE subtechniques
* Add GUIDs back in, attack_technique to string (#1019 )
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* Subtechnique transfer T1220-T1546.005 (#1020 )
* Create T1222.001.yaml
* Create T1222.002.yaml
* Create T1505.002.yaml
* Update T1543.003.yaml
* Update AtomicService.cs
* Update T1546.005.yaml
* Delete T1222.yaml
* Update T1482.yaml
* Update T1485.yaml
* Update T1220.yaml
* Update T1489.yaml
* Update T1490.yaml
* Update T1496.yaml
* Update T1505.003.yaml
* Update T1505.yaml
* Update T1518.001.yaml
* Update T1518.yaml
* Update T1529.yaml
* Update T1543.004.yaml
* Update T1546.001.yaml
* Update T1546.002.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.002.yaml
* Update T1543.001.yaml
* Update T1518.001.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1531.yaml
* Update T1222.001.yaml
* Update T1222.002.yaml
* Update T1505.002.yaml
* Update T1505.003.yaml
* Update T1518.001.yaml
* Update T1543.001.yaml
* Update T1546.005.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.003.yaml
* Update T1543.002.yaml
* added auto_generated_guid 1220
* added T1222.001 auto_generated_guid
* Update T1222.002.yaml
added auto_generated_guid entries
* Update T1482.yaml
auto_generated_guid added
* Update T1485.yaml
added auto_generated_guids
* Update T1489.yaml
added auto_generated_guids
* Update T1490.yaml
added auto_generated_guids
* Update T1496.yaml
added auto_generated_guid
* Update T1505.002.yaml
added auto_generated_guid from old T1505 same atomic
* Update T1505.003.yaml
added auto_generated_guid from previous atomic 1100
* Delete T1505.yaml
no longer needed, moved to 1505.002
* Update T1518.yaml
added auto_generated_guids
* Update T1529.yaml
added auto_generated_guids
* Update T1531.yaml
added auto_generated_guids
* Update T1543.001.yaml
added auto_generated_guid
* Update T1543.002.yaml
added auto_generated_guid
* Update T1543.004.yaml
added auto_generated_guid
* Update T1546.001.yaml
added auto_generated_guid
* Update T1546.002.yaml
added auto_generated_guid
* Update T1546.003.yaml
* Update T1546.004.yaml
added auto_generated_guid
* Update T1546.005.yaml
added auto_generated_guid
* add guids back in
* fix spacing issue
* fix spacing
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Sub-techniques T1053-T1113 - Updates (#1022 )
* Sub-techniques T1053-T1113 - Updates
Updated techniques for sub-techniques.
* minor fixes
format fixing
* Added GUIDs
- Added GUIDs back
- Fixed typo (T1054)
- Fixed attack_technique from an array to a string
* Sub-technique updates T1546.008 through T1574.011 (#1024 )
* sub technique updates
* sub technique updates
* sub technique updates
* Carrie updates (#1017 )
* updated T1110,12,13
* updated T1114
* updated T1114
* updated T1115
* updated T1119
* updated T1123,24
* updated T1127
* updated T1114
* updated T1127
* updated T1132
* T1134.004
* T1134.004
* updated T1135
* updated T1136
* updated T1137
* updated T1140
* remove depracted T1153
* updated T1176
* updated T1197
* updated T1201
* updated T1202
* updated T1204
* updated T1207
* updated T1216
* updated T1204
* updated T1217
* updated T1218
* updated T1218
* updated T1219
* updated T1218
* attack_technique to string
* Subtechnique transfer (#1025 )
* T1003 review
* T1005 manual review changes
* T1027.002 sub-technique review
* T1027.004 sub-technique review
* T1036 sub-technique review
* T1037 sub-technique review
* T1048 sub-technique review
* YAML bugfixes
* Adding auto-generated GUIDs back to tests
* merging with Mike's PR
* Merging with Carrie's PR
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Subtechnique fix (#1026 )
* add atomic_tests: element
* add atomic_tests: element
* more fixes
* more fixes
* more fixes
* sub technique minor fixes 1 (#1027 )
* fixes
* fixes
* more fixes
* more fixes
* display name fix (#1028 )
* remove some deprecated stuff. reorganize a little (#1031 )
* Gendocs fix (#1033 )
* gendocs updates for subtechniques
* add folders
* ignore auto generated markdown files
* remove tmp files
* add tmp files
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
* navigator layer v3.0
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
Co-authored-by: Matt Graeber <60448025+mgraeber-rc@users.noreply.github.com >
Co-authored-by: Tsora-Pop <35981510+Tsora-Pop@users.noreply.github.com >
Co-authored-by: Michael Haag <mike@redcanary.com >
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-06-17 12:55:46 -06:00