Commit Graph

5173 Commits

Author SHA1 Message Date
Atomic Red Team GUID generator 05fc04f419 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-02-26 15:17:09 +00:00
chefengineer a09cebd1a3 Adding new test for T1654 for Enumerate Windows Security Log (#2704)
* Adding new test for T1654 for Enumerate Windows Security Log via WevtUtil

Adding new test for T1654 for Enumerate Windows Security Log via WevtUtil

* Update T1654.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-26 09:16:32 -06:00
Atomic Red Team doc generator ae87c3e185 Generated docs from job=generate-docs branch=master [ci skip] 2024-02-25 01:15:48 +00:00
Atomic Red Team GUID generator 21401622e4 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-02-25 01:15:31 +00:00
Hare Sudhan bf630ecb29 fix guid error (#2696) 2024-02-24 18:14:49 -07:00
BF 4e15393878 Update T1613.yaml
Renamed the atomics
2024-02-22 16:32:03 -05:00
KillrBunn3 1202d62c59 New test: T1218.011 Gamarue tradecraft commandline with rundll32 execution (#2678)
* New test: T1218.011 Gamarue tradecraft commandline with rundll32 execution

* Update T1218.011.yaml

* Update T1218.011.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-22 15:29:05 -06:00
Daniel Cortez 0bd9b1acc1 New Test T1137.001 - 'Office Application Startup: Office Template Macros.' (#2694)
* Create T1137.001.yml

Created new Directory and new test for T1137.001

* Rename T1137.001.yml to T1137.001.yaml

* Update T1137.001.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-22 14:56:04 -06:00
jianni20 df24b972a9 New test: T1003.003 - Create Volume Shadow Copy with diskshadow (#2690)
* New test - Create Volume Shadow Copy with diskshadow

* Fix typos

* fix indentation

* Update T1003.003.yaml

* Update T1003.003.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-22 14:06:29 -06:00
adelfavero57 eba0f8ea61 Esxi atomic tests batch 2 (#2650)
* initial esxi commit

* second commit esxi

* use ExternalPayloads folder

* use ExternalPayloads folder

---------

Co-authored-by: clr2of8 <clr2of8@gmail.com>
2024-02-22 13:48:23 -06:00
sai prashanth pulisetti d234ade71d Merge branch 'master' into patch-7 2024-02-23 00:57:38 +05:30
Atomic Red Team doc generator 77a44aea50 Generated docs from job=generate-docs branch=master [ci skip] 2024-02-22 17:37:16 +00:00
Atomic Red Team GUID generator ed31f26ba9 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-02-22 17:37:00 +00:00
Michael Haag 8f71cf4d53 SOAPHound (#2689)
* SOAPHound

* Updates

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-22 11:36:17 -06:00
Atomic Red Team doc generator a840cf6245 Generated docs from job=generate-docs branch=master [ci skip] 2024-02-21 16:26:59 +00:00
Carrie Roberts af13a59177 remove atomic w/broken bitly link (#2693) 2024-02-21 11:25:36 -05:00
BF 31bba55b31 Merge pull request #4 from W00glin/T1613_Dockerfile
Update Dockerfile
2024-02-12 10:55:02 -08:00
BF 557b121cd1 Update Dockerfile
Fixed typo
2024-02-12 13:53:34 -05:00
BF 7166f9a24b Update T1613.yaml 2024-02-12 13:23:44 -05:00
BF 05f1ec8f2a Updated Dockerfile 2024-02-12 13:23:13 -05:00
BF 3f7f18183e Update T1613.md 2024-02-12 13:22:20 -05:00
Atomic Red Team doc generator 86c88bc4d1 Generated docs from job=generate-docs branch=master [ci skip] 2024-02-09 14:59:36 +00:00
Atomic Red Team GUID generator 15e983365f Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-02-09 14:59:20 +00:00
traceflow 50512fcc95 Adding ASR rules deletion (#2683)
* adding ASR rules deletion

* adding ASR rules deletion

* adding ASR rules deletion

* adding ASR rules deletion

* adding ASR rules deletion

* adding ASR rules deletion

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-09 08:58:45 -06:00
Atomic Red Team doc generator 98f9300887 Generated docs from job=generate-docs branch=master [ci skip] 2024-02-08 21:39:53 +00:00
Atomic Red Team GUID generator ded6414060 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-02-08 21:39:40 +00:00
Thomas M f92569597a Add new atomic test T1055 custom uuid process injection in C, a stealthier implementation compares to the original one introduced by NCC group (#2674)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-08 15:39:08 -06:00
Atomic Red Team doc generator dea1cd7641 Generated docs from job=generate-docs branch=master [ci skip] 2024-02-08 21:36:56 +00:00
Atomic Red Team GUID generator a9326f2654 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-02-08 21:36:40 +00:00
Thomas M 18ba41456e T1027.007 Obfuscated Files or Information: Dynamic API Resolution: ninja syscall (#2673)
* Add new atomic test T1027.007 Obfuscated Files or Information: Dynamic API Resolution

* Add new atomic test T1027.007 Obfuscated Files or Information: Dynamic API Resolution

* Add new atomic test T1027.007 Obfuscated Files or Information: Dynamic API Resolution

* Add new atomic test T1027.007 Obfuscated Files or Information: Dynamic API Resolution

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-08 15:35:56 -06:00
Atomic Red Team doc generator 669e685b8d Generated docs from job=generate-docs branch=master [ci skip] 2024-02-08 21:29:25 +00:00
Jake H a4653ac9b5 Updating get_prereq_command to download and install python3 & pip (#2680)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-08 15:28:39 -06:00
Atomic Red Team doc generator 1e4d33d15a Generated docs from job=generate-docs branch=master [ci skip] 2024-02-08 21:23:17 +00:00
Jake H 694d2c0778 Removing REM from 95b25212-91a7-42ff-9613-124aca6845a8 due to incorrect execution (#2681)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-02-08 15:22:25 -06:00
Koustav Choudhury c1a770844d Excel spelling typo (#2682) 2024-02-08 15:17:19 -06:00
Atomic Red Team doc generator 02c7d02fe1 Generated docs from job=generate-docs branch=master [ci skip] 2024-02-05 16:49:04 +00:00
Emile Marty 12f5d9d323 Update T1490.yaml (#2677)
* Update T1490.yaml

Fixed a formatting error in #2676

* Update T1490.yaml

add dependency_executor_name field

---------

Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2024-02-05 09:48:15 -07:00
Atomic Red Team doc generator e30f9b573f Generated docs from job=generate-docs branch=master [ci skip] 2024-02-05 16:43:49 +00:00
Atomic Red Team GUID generator a5bf6bad39 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-02-05 16:43:32 +00:00
Kyaw-Pyiyt-Htet 25515b8f72 Mikoyan dee patch 1 (#2679)
* Update T1040.yaml

PowerShell cmdlets to capture network traffic

* Update T1040.yaml

* Update T1040.yaml
2024-02-05 09:42:53 -07:00
sai prashanth pulisetti 0b6af7cafb Merge branch 'master' into patch-7 2024-02-05 10:23:16 +05:30
Atomic Red Team doc generator 0e202df355 Generated docs from job=generate-docs branch=master [ci skip] 2024-01-31 23:30:28 +00:00
Emile Marty 2a194cdc34 Added support for T1490 creating shadow copies in Windows 10+ (#2676)
* Update T1490.yaml

Support for creating shadow copies in Windows 10+

* Update T1490.md

Updating documentation

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-01-31 17:29:42 -06:00
Atomic Red Team doc generator ed9cb8cdc7 Generated docs from job=generate-docs branch=master [ci skip] 2024-01-31 23:27:05 +00:00
Atomic Red Team GUID generator 24c9dc3212 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-01-31 23:26:50 +00:00
sai prashanth pulisetti e9051bed60 Update T1490.yaml "Modify VSS Service Permissions" (#2668)
* Update T1490.yaml "Modify VSS Service Permissions"

Modify permissions of the VSS service to inhibit system recovery. This test alters the security settings of the Volume Shadow Copy Service (VSS), potentially impacting system recovery operations. It should be conducted only in a controlled environment. The executor must have administrative privileges to modify service permissions. Note that this test does not include a cleanup command; thus, the changes will persist after execution. Ensure that you have a backup or a system recovery plan in place before running this test. Running this test on a production system or critical environment is not recommended without proper precautions.

* Update T1490.yaml

updated guid

* Update T1490.yaml

updated description and clean up command

* Update T1490.yaml

updated indentations

* Update T1490.yaml

* Update T1490.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-01-31 17:26:10 -06:00
zaicurity dc264a80f4 Added T1562.010 Test for PowerShell v2 Downgrade (#2670)
* Added T1562.010 Test for PowerShell v2 Downgrade

* Remove PowerShell Downgrade Attack atomic from T1059.001.yaml
2024-01-31 17:22:30 -06:00
sai prashanth pulisetti 949710153d Merge branch 'master' into patch-7 2024-01-30 00:56:38 +05:30
Atomic Red Team doc generator 45138fdb07 Generated docs from job=generate-docs branch=master [ci skip] 2024-01-29 16:24:34 +00:00
Atomic Red Team GUID generator 5836fe0a80 Generate GUIDs from job=generate-docs branch=master [skip ci] 2024-01-29 16:24:22 +00:00