Commit Graph

5173 Commits

Author SHA1 Message Date
Atomic Red Team doc generator ddc13a93da Generated docs from job=generate-docs branch=master [ci skip] 2023-10-10 17:04:13 +00:00
Carrie Roberts 4133575f2e use command prompt (#2559)
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2023-10-10 11:03:10 -06:00
Atomic Red Team doc generator 4b58fa4f25 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-10 16:05:30 +00:00
Carrie Roberts e8d26acbc7 use cmd.exe syntax for temp dir (#2558)
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2023-10-10 10:04:16 -06:00
Atomic Red Team doc generator 3625d11dd4 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-10 15:57:18 +00:00
Carrie Roberts 07da073a66 fix command (#2557) 2023-10-10 09:55:20 -06:00
Atomic Red Team doc generator 04e487c182 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:26:58 +00:00
Carrie Roberts 62f83972c5 use external payloads directory (#2554)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-07 15:25:51 -04:00
Atomic Red Team doc generator a08834a85c Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:21:34 +00:00
Carrie Roberts 076d228371 quote path (#2555)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-07 15:20:38 -04:00
Atomic Red Team doc generator c0a77d2d6d Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:10:44 +00:00
Carrie Roberts 8666118b4b no prompt for confirmation (#2553)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-07 15:09:32 -04:00
Atomic Red Team doc generator 008fc61040 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:07:22 +00:00
Atomic Red Team GUID generator 9fcde0a924 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-07 19:07:01 +00:00
Carrie Roberts 72585c9dd7 fix typo (#2556) 2023-10-07 15:05:53 -04:00
Jonathan 81368acdd7 Add T1056.002 Gui Input Capture macOS test (#2531)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-03 17:22:55 -04:00
Atomic Red Team doc generator 5e4a0cea17 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-03 17:49:04 +00:00
Atomic Red Team GUID generator 34e755969e Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-03 17:48:44 +00:00
Swachchhanda Shrawan Poudel 9026f98900 Added few new tests for T1518.001 and also rdrleakdiag.exe test accessing lsass (#2550)
* Added lolbin rdrleakdiag support for lsass dumping and some Security Software Discovery tests

* Changes done as suggested

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-10-03 11:48:00 -06:00
Atomic Red Team doc generator a007c274f6 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-03 17:39:50 +00:00
Carrie Roberts d667fffea2 correct url (#2552)
* correct url

* Update T1027.yaml
2023-10-03 11:38:37 -06:00
Atomic Red Team doc generator 302abbb7b7 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-03 11:06:39 +00:00
Atomic Red Team GUID generator 4b343f18ab Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-03 11:06:21 +00:00
socketz 99e7f006f1 T1055.011 - Process Injection: Extra Window Memory Injection (#2539)
* Updated .gitignore with more files to be ignored

* Working T1055.011 x64 payload. WIP x86

* Fixed a bug executing from Invoke-AtomicTest. x86 WIP

* Update T1055.011.yaml

Removed autogenerated_guid

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-03 07:05:41 -04:00
Atomic Red Team doc generator b2204555cf Generated docs from job=generate-docs branch=master [ci skip] 2023-10-02 20:45:35 +00:00
Atomic Red Team GUID generator 19c71c2a40 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-02 20:45:17 +00:00
Mohana Shankar D 3397666c5c New Atomic Test: PromptOnSecureDesktop (#2549)
* New Atomic Test: PromptOnSecureDesktop

* Update T1548.002.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-10-02 14:44:36 -06:00
traceflow 30947260a6 adding test simulating DarkGate malware writing script to file from cmd (#2548)
* adding test simulating DarkGate malware writing script to file from cmd

* adding test simulating DarkGate malware writing script to file from cmd

* updating atomics count in README.md [ci skip]

---------

Co-authored-by: publish bot <opensource@redcanary.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:52:48 -06:00
Atomic Red Team doc generator d387c3e718 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:51:00 +00:00
Atomic Red Team GUID generator 971f54bdf9 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-29 14:50:42 +00:00
Swachchhanda Shrawan Poudel 247349eb5c Added new tests for techniques T1082 and T1070 (#2547)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:50:02 -06:00
Atomic Red Team doc generator 9bf809338a Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:45:43 +00:00
Atomic Red Team GUID generator 33aa1e0df2 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-29 14:45:20 +00:00
Tuutaans 2dc70561dd Provlaunch.exe Executes Arbitrary Command via Registry Key (#2546)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:44:32 -06:00
Atomic Red Team doc generator ccdf46f389 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:41:30 +00:00
Antonio Piazza f68822b349 Added ExternalPayloads directory (#2545)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

* Update T1110.004.yaml

Added Powershell Command to creat ExternalPayloads dir for the second prereq for procedure 4852c630-87a9-409b-bb5e-5dc12c9ebcde.

* Update T1110.001.yaml

Added ExrernalPayload directory creation PowerShell command for procedure 59dbeb1a-79a7-4c2a-baf4-46d0f4c761c4
prereq 2

* Added ExternalPayloads Dir

Added Powershell command to create new ExternalPayloads dir for procedure fad04df1-5229-4185-b016-fb6010cd87ac

* Add ExternalPayloads Dir

Added PowerShell Command to create new ExternalPayloads directory for procedure c6f25ec3-6475-47a9-b75d-09ac593c5ecb

* Added prereq download directories

Added powershell command to create prereq download directories for procedure 6f2c5c87-a4d5-4898-9bd1-47a55ecaf1dd

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:40:27 -06:00
zaicurity 273e3c0fb7 Fix T1083-6 DirLister PreReqs (#2541)
* Fix T1083-6 DirLister PreReqs

A quote symbol in the get_prereq_command was wrong which caused the directory name to include "-Force". Due to this the script failed.

* updating atomics count in README.md [ci skip]

---------

Co-authored-by: publish bot <opensource@redcanary.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:35:42 -06:00
Atomic Red Team doc generator dc194fadf2 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:31:57 +00:00
Antonio Piazza b524d93bad New ExternalPayloads dir creation (#2544)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

* Update T1110.004.yaml

Added Powershell Command to creat ExternalPayloads dir for the second prereq for procedure 4852c630-87a9-409b-bb5e-5dc12c9ebcde.

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:31:00 -06:00
Atomic Red Team doc generator 098dfbfe5b Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:27:05 +00:00
Antonio Piazza a301206811 Download Directory creation (#2543)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:26:08 -06:00
Atomic Red Team doc generator d146373e1f Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:24:07 +00:00
Antonio Piazza 7c61ce15f0 Update T1036.yaml (#2542)
Added ExternalPayloads directory creation via powershell command for procedure 4449c89b-ec82-43a4-89c1-91e2f1abeecc
2023-09-25 14:22:53 -06:00
Atomic Red Team doc generator 81692e20cd Generated docs from job=generate-docs branch=master [ci skip] 2023-09-23 03:44:15 +00:00
Carrie Roberts fc3bfecda2 use ExternalPayloads folder (#2538) 2023-09-22 23:43:06 -04:00
Atomic Red Team doc generator 78204c6965 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-22 21:07:21 +00:00
final five three fantasy 31713d27c6 updated lazagne URL (#2536)
* Repair path error

* Repair path error

* Update dependency URL

* Update T1555.003.yaml

---------

Co-authored-by: ywliang <ywliang@Hillstonenet.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-22 15:06:06 -06:00
Atomic Red Team doc generator a228ee8656 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-22 19:15:21 +00:00
Antonio Piazza e3b45b7b30 Added ExternalPayloads dir creation (#2537)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173
2023-09-22 13:14:23 -06:00
Carrie Roberts d4709021fb Handle spaces in file paths (#2535)
* updating atomics count in README.md [ci skip]

* wip

* handle spaces in path

* update readme

* fix typo

---------

Co-authored-by: publish bot <opensource@redcanary.com>
2023-09-22 10:47:25 -06:00