Atomic Red Team doc generator
6a94940f80
Generated docs from job=generate-docs branch=master [ci skip]
2025-04-08 22:48:52 +00:00
Mattis
9e93193646
updated T1569.002 Use PsExec to execute a command on a remote host ( #3090 )
...
Co-authored-by: Mattis Swannet <mattis.swannet@nynox.eu >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2025-04-08 17:47:54 -05:00
Atomic Red Team doc generator
5ede8f21e4
Generated docs from job=generate-docs branch=master [ci skip]
2025-02-13 22:03:40 +00:00
Atomic Red Team doc generator
444f81d64f
Generated docs from job=generate-docs branch=master [ci skip]
2024-07-24 02:28:03 +00:00
Pavan R Patil
7c1d934430
Update T1569.002.yaml ( #2869 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2024-07-23 21:26:56 -05:00
Atomic Red Team doc generator
e855218dba
Generated docs from job=generate-docs branch=master [ci skip]
2024-05-15 00:55:00 +00:00
abhijose09
efa3370b62
Update T1569.002.yaml ( #2776 )
...
* Update T1569.002.yaml
Added new test Modifying ACL of Service Control Manager via SDET
* correction
---------
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
Co-authored-by: Hare Sudhan <code@0x6c.dev >
2024-05-14 20:53:45 -04:00
Atomic Red Team doc generator
a228ee8656
Generated docs from job=generate-docs branch=master [ci skip]
2023-09-22 19:15:21 +00:00
Carrie Roberts
d4709021fb
Handle spaces in file paths ( #2535 )
...
* updating atomics count in README.md [ci skip]
* wip
* handle spaces in path
* update readme
* fix typo
---------
Co-authored-by: publish bot <opensource@redcanary.com >
2023-09-22 10:47:25 -06:00
Atomic Red Team doc generator
868f5477f6
Generated docs from job=generate-docs branch=master [ci skip]
2023-06-15 19:53:19 +00:00
Carrie Roberts
586818a01f
use ExternalPayloads folder ( #2462 )
...
* use ExternalPayloads folder
* psexec as external dependency
* psexec as external dependency
2023-06-15 13:52:16 -06:00
Atomic Red Team doc generator
cef46e4479
Generated docs from job=generate-docs branch=master [ci skip]
2023-06-15 16:17:12 +00:00
Carrie Roberts
068d32b1ea
use ExternalPayloads directory ( #2460 )
...
* use ExternalPayloads directory
* use ExternalPayloads directory
* use ExternalPayloads directory
2023-06-15 10:16:12 -06:00
Atomic Red Team doc generator
b1f3c968f2
Generated docs from job=generate-docs branch=master [ci skip]
2023-05-19 17:06:33 +00:00
Atomic Red Team GUID generator
2a51677203
Generate GUIDs from job=generate-docs branch=master [skip ci]
2023-05-11 20:40:32 +00:00
Michael Haag
1ebcb346f6
Snake Malware Atomic Tests
2023-05-11 12:40:31 -06:00
Atomic Red Team doc generator
41355dea4e
Generated docs from job=generate-docs branch=master [ci skip]
2023-03-20 19:39:02 +00:00
Atomic Red Team GUID generator
8a83c877bb
Generate GUIDs from job=generate-docs branch=master [skip ci]
2023-03-20 19:38:46 +00:00
Darin Manley
29063f5306
Added RemCom to execute a command on a remote host ( #2380 )
...
* Added RemCom to execute a command on a remote host
* Update T1569.002.yaml
---------
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com >
2023-03-20 13:38:17 -06:00
Atomic Red Team doc generator
16594d72c5
Generated docs from job=generate-docs branch=master [ci skip]
2023-02-13 23:11:19 +00:00
Josh Rickard
a5dd0813cd
fix: Updating atomics YAML file structure to align with the new JSON schema definition ( #2323 )
...
* fix: Updating atomics YAML file structure to align with the new JSON schema definition.
This also fixes some white space issues and general line formatting across all impacted atomics.
* fix: One additional change needed
---------
Co-authored-by: MSAdministrator <MSAdministrator@users.noreply.github.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2023-02-13 16:10:37 -07:00
Atomic Red Team doc generator
d0dad62dbc
Generated docs from job=generate-docs branch=master [ci skip]
2022-09-23 22:57:18 +00:00
Atomic Red Team doc generator
5ec9b7c317
Generated docs from job=generate-docs branch=master [ci skip]
2022-07-25 20:54:13 +00:00
Atomic Red Team GUID generator
e935cc7fe5
Generate GUIDs from job=generate-docs branch=master [skip ci]
2022-07-25 20:54:06 +00:00
dwhite9
e4945a7c50
T1569.002 - Added Atomic to emulate BlackCat malware using embedded PsExec binary ( #2043 )
...
* Added Atomic to emulate BlackCat malware using embedded PsExec binary
(placed in /bin dir)
* add blog links
Co-authored-by: Daniel White <d0w019h@homeoffice.wal-mart.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-07-25 14:53:35 -06:00
CircleCI Atomic Red Team doc generator
72fc6bd787
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-04-14 22:38:49 +00:00
CircleCI Atomic Red Team GUID generator
d5c079a274
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-04-14 22:38:42 +00:00
Eloy
0d952f9271
add Impacket psexec test to T1569.002 ( #1862 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-04-14 16:38:05 -06:00
CircleCI Atomic Red Team doc generator
7091fa8b16
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-04-01 14:37:00 +00:00
CircleCI Atomic Red Team doc generator
21bffa7a69
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-10-18 14:55:17 +00:00
Clément Notin
067187c3ba
T1569.002: fix spelling ( #1650 )
2021-10-18 08:54:54 -06:00
CircleCI Atomic Red Team doc generator
bc21f59ff0
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-09-04 00:21:31 +00:00
Josh Rickard
1513717eb2
Updating atomics to conform to standard ( #1619 )
...
* Updated format of input_argument types for Url
* Updated type for input_arguments to Url (missed)
* Updating Path type for input_arguments
* Updated String type for input_arguments
* Missed a few Strings and Url types
* Updated default values for input_arguments to align with their types
* Updated Integer type for input_arguments
* Updated formatting and spacing of atomics
2021-09-03 18:20:46 -06:00
CircleCI Atomic Red Team doc generator
36d49de4c8
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 17:04:33 +00:00
CircleCI Atomic Red Team doc generator
575b36a8e6
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 15:16:54 +00:00
CircleCI Atomic Red Team doc generator
adc459fbf7
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-04-08 13:10:07 +00:00
Ryan
ba13a01daf
Update T1569.002.yaml ( #1414 )
...
I was failing to pass the precheck without adding in the dependency_executor_name parameter. Something with parsing I believe
2021-04-08 07:09:43 -06:00
CircleCI Atomic Red Team doc generator
910a2a764a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-09-29 13:53:28 +00:00
CircleCI Atomic Red Team doc generator
aaf9b7500e
Generate docs from job=validate_atomics_generate_docs branch=master
2020-09-18 14:44:29 +00:00
cnotin
6000965b1e
T1028 "Windows Remote Management": split in several techniques
...
Fixes #1042
2020-09-18 15:57:11 +02:00
CircleCI Atomic Red Team doc generator
979befcf8a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-07-20 17:44:44 +00:00
JB
b3da61d0a4
Improved automation by adding -accepteula option ( #1144 )
...
* added -accepteula flag for PsExec
will make test seamless and fully automatable
ref https://github.com/redcanaryco/atomic-red-team/issues/1092
* Added reference to making tests not require interaction like -accepteula -q options
* added -accepteula to PsExec command
will make it automated
* Added /accepteula option to Autoruns execution in test 1
prior this may have prevented full automation of the test
* Update spec.yaml
* typo, nice catch cnotin
Co-authored-by: Clément Notin <clement@notin.org >
* fixing mystery text accidentally added to branch (rm'd)
* added -accepteula on psexec test, thanks @cnotin for the catch!
* added back in word, 'manually' removed in last pull acc.
thanks @cnotin
* removing /accepteula proposed previously, from test 1
Co-authored-by: Clément Notin <clement@notin.org >
2020-07-20 11:44:23 -06:00
CircleCI Atomic Red Team doc generator
2235ae41d2
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-25 21:48:15 +00:00
Clément Notin
75bf6ed382
T1569.002: fix psexec prereq install ( #1043 )
...
Create folder for psexec_exe
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-25 15:47:00 -06:00
CircleCI Atomic Red Team doc generator
6bb3c3351d
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-19 22:23:26 +00:00
Clément Notin
0e29cc757c
T1569.002-1: add cleanup ( #1069 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-19 16:22:52 -06:00
CircleCI Atomic Red Team doc generator
c77258e6fb
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-19 16:30:34 +00:00
JrOrOneEquals1
08a1750179
fix quoting issue ( #1071 )
2020-06-19 10:30:09 -06:00
CircleCI Atomic Red Team doc generator
8a82e9b66a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-18 01:57:35 +00:00
Carrie Roberts
24549e3866
Convert to Mitre ATT&CK sub-technique schema ( #1056 )
...
* Initial transfer of atomics to MITRE subtechniques
* Add GUIDs back in, attack_technique to string (#1019 )
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* Subtechnique transfer T1220-T1546.005 (#1020 )
* Create T1222.001.yaml
* Create T1222.002.yaml
* Create T1505.002.yaml
* Update T1543.003.yaml
* Update AtomicService.cs
* Update T1546.005.yaml
* Delete T1222.yaml
* Update T1482.yaml
* Update T1485.yaml
* Update T1220.yaml
* Update T1489.yaml
* Update T1490.yaml
* Update T1496.yaml
* Update T1505.003.yaml
* Update T1505.yaml
* Update T1518.001.yaml
* Update T1518.yaml
* Update T1529.yaml
* Update T1543.004.yaml
* Update T1546.001.yaml
* Update T1546.002.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.002.yaml
* Update T1543.001.yaml
* Update T1518.001.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1531.yaml
* Update T1222.001.yaml
* Update T1222.002.yaml
* Update T1505.002.yaml
* Update T1505.003.yaml
* Update T1518.001.yaml
* Update T1543.001.yaml
* Update T1546.005.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.003.yaml
* Update T1543.002.yaml
* added auto_generated_guid 1220
* added T1222.001 auto_generated_guid
* Update T1222.002.yaml
added auto_generated_guid entries
* Update T1482.yaml
auto_generated_guid added
* Update T1485.yaml
added auto_generated_guids
* Update T1489.yaml
added auto_generated_guids
* Update T1490.yaml
added auto_generated_guids
* Update T1496.yaml
added auto_generated_guid
* Update T1505.002.yaml
added auto_generated_guid from old T1505 same atomic
* Update T1505.003.yaml
added auto_generated_guid from previous atomic 1100
* Delete T1505.yaml
no longer needed, moved to 1505.002
* Update T1518.yaml
added auto_generated_guids
* Update T1529.yaml
added auto_generated_guids
* Update T1531.yaml
added auto_generated_guids
* Update T1543.001.yaml
added auto_generated_guid
* Update T1543.002.yaml
added auto_generated_guid
* Update T1543.004.yaml
added auto_generated_guid
* Update T1546.001.yaml
added auto_generated_guid
* Update T1546.002.yaml
added auto_generated_guid
* Update T1546.003.yaml
* Update T1546.004.yaml
added auto_generated_guid
* Update T1546.005.yaml
added auto_generated_guid
* add guids back in
* fix spacing issue
* fix spacing
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Sub-techniques T1053-T1113 - Updates (#1022 )
* Sub-techniques T1053-T1113 - Updates
Updated techniques for sub-techniques.
* minor fixes
format fixing
* Added GUIDs
- Added GUIDs back
- Fixed typo (T1054)
- Fixed attack_technique from an array to a string
* Sub-technique updates T1546.008 through T1574.011 (#1024 )
* sub technique updates
* sub technique updates
* sub technique updates
* Carrie updates (#1017 )
* updated T1110,12,13
* updated T1114
* updated T1114
* updated T1115
* updated T1119
* updated T1123,24
* updated T1127
* updated T1114
* updated T1127
* updated T1132
* T1134.004
* T1134.004
* updated T1135
* updated T1136
* updated T1137
* updated T1140
* remove depracted T1153
* updated T1176
* updated T1197
* updated T1201
* updated T1202
* updated T1204
* updated T1207
* updated T1216
* updated T1204
* updated T1217
* updated T1218
* updated T1218
* updated T1219
* updated T1218
* attack_technique to string
* Subtechnique transfer (#1025 )
* T1003 review
* T1005 manual review changes
* T1027.002 sub-technique review
* T1027.004 sub-technique review
* T1036 sub-technique review
* T1037 sub-technique review
* T1048 sub-technique review
* YAML bugfixes
* Adding auto-generated GUIDs back to tests
* merging with Mike's PR
* Merging with Carrie's PR
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Subtechnique fix (#1026 )
* add atomic_tests: element
* add atomic_tests: element
* more fixes
* more fixes
* more fixes
* sub technique minor fixes 1 (#1027 )
* fixes
* fixes
* more fixes
* more fixes
* display name fix (#1028 )
* remove some deprecated stuff. reorganize a little (#1031 )
* Gendocs fix (#1033 )
* gendocs updates for subtechniques
* add folders
* ignore auto generated markdown files
* remove tmp files
* add tmp files
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
* navigator layer v3.0
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
Co-authored-by: Matt Graeber <60448025+mgraeber-rc@users.noreply.github.com >
Co-authored-by: Tsora-Pop <35981510+Tsora-Pop@users.noreply.github.com >
Co-authored-by: Michael Haag <mike@redcanary.com >
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-06-17 12:55:46 -06:00