Commit Graph

5173 Commits

Author SHA1 Message Date
Adam Mashinchi 1de3dd9eee Merge branch 'master' into amashinchi-rc-patch-1 2021-07-27 07:49:43 -07:00
Adam Mashinchi 1496e7bbcc Merge branch 'master' into T1027-obfuscated-powershell 2021-07-27 07:47:37 -07:00
CircleCI Atomic Red Team doc generator 29a063b40b Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:47:14 +00:00
CircleCI Atomic Red Team GUID generator e2cbd60596 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:47:07 +00:00
Adam Mashinchi cc530f1d00 Merge branch 'master' into T1027-obfuscated-powershell 2021-07-27 07:46:37 -07:00
Adam Mashinchi e6009bdbb3 Merge branch 'master' into T1059.001-obfuscated-powershell 2021-07-27 07:45:02 -07:00
CircleCI Atomic Red Team doc generator 1d8ca6c672 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:44:55 +00:00
CircleCI Atomic Red Team GUID generator 5e1b13f76f Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:44:49 +00:00
Adam Mashinchi e787817cf8 Merge branch 'master' into T1059.001-obfuscated-powershell 2021-07-27 07:44:28 -07:00
Adam Mashinchi 48c159d3ea Merge branch 'master' into T1059.003-suspicious-execution 2021-07-27 07:43:27 -07:00
CircleCI Atomic Red Team doc generator 5956ac532b Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:42:34 +00:00
Adam Mashinchi 54f1913243 Merge branch 'master' into T1059.003-suspicious-execution 2021-07-27 07:42:29 -07:00
CircleCI Atomic Red Team GUID generator d55b581331 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:42:28 +00:00
Matt Graeber 0960fca14e Update T1059.001.yaml
Removing extra space in line 379
2021-07-27 09:47:29 -04:00
Bhavin Patel 8a87508ccd Merge branch 'master' into platform-change-T1611 2021-07-26 15:14:33 -07:00
Adam Mashinchi 2a3885fb14 Added example to T1218.005 without network call 2021-07-26 13:08:40 -07:00
Adam Mashinchi e8899b4df6 Additional PowerShell Download in T1105 2021-07-26 13:00:42 -07:00
Adam Mashinchi 64966be2fd Add Suspicious Execution to T1059.003 2021-07-26 12:57:10 -07:00
Adam Mashinchi ba20bcd95a Add obfuscated PowerShell to T1059.001
Additional obfuscated PowerShell example.
2021-07-26 12:52:18 -07:00
Adam Mashinchi 189ae94750 Update T1027.yaml
Added additional obfuscated PowerShell example.
2021-07-26 12:46:41 -07:00
biot 61e63128be fixed user_account 2021-07-22 14:35:54 +01:00
biot a8288151db removed blank lines 2021-07-21 17:46:15 +01:00
biot 244536527b fix typo 2021-07-21 17:40:24 +01:00
sc0o da81e35786 fix(T1222.002): recursive chmod and chown for macos 2021-07-21 16:43:18 +02:00
biot 2947b8d3da T1056.001 2021-07-20 23:46:53 +01:00
Thomas Gardner 84b812aff1 Merge branch 'master' into t1140_extended 2021-07-19 15:48:07 -06:00
CircleCI Atomic Red Team doc generator 4ab80721ac Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-19 21:21:58 +00:00
Josh Rickard 9d2212bd20 T1543.004 - Updated cleanup key (#1553)
Updated the key `cleanup` to `cleanup_command` to conform to other tests.

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2021-07-19 15:21:15 -06:00
CircleCI Atomic Red Team doc generator 0f8eb34b74 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-19 21:20:24 +00:00
Josh Rickard 842a5df879 T1056.001 - Updating dependencies (#1555)
* T1056.001 - Updating dependencies

Moved `prereq_command` and `get_prereq_command` under dependencies to conform to other tests

* white space correction

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2021-07-19 15:19:59 -06:00
CircleCI Atomic Red Team doc generator 6f2bf060fb Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-19 20:51:52 +00:00
Josh Rickard df34cadff9 T1135 - Fixed key name in executor test (#1552)
* Fixed key name of `elevation_require` to `elevation_required`
2021-07-19 14:51:21 -06:00
CircleCI Atomic Red Team doc generator 4af8bae9f4 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-14 17:14:29 +00:00
CircleCI Atomic Red Team GUID generator 1f82f6af1f Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-14 17:14:23 +00:00
Jay_darknight d42bda32a1 Dump svchost.exe to gather RDP plaintext credential (#1551) 2021-07-14 11:13:59 -06:00
CircleCI Atomic Red Team doc generator d50e69b5c8 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-09 15:35:13 +00:00
Carrie Roberts 79e706f2df fix cleanup cmd as per issue #1543 (#1548) 2021-07-09 09:34:32 -06:00
CircleCI Atomic Red Team doc generator b51f415e30 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:23:38 +00:00
CircleCI Atomic Red Team GUID generator 6c2c28f497 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:23:32 +00:00
Clément Notin 2411b36008 T1098.001: implement AAD application hijacking tests (#1454)
* T1098.001: implement AAD application hijacking tests

Create Azure AD Application Hijacking Tests

* T1098.001 : add end of test string

* T1098.001: use new "azure-ad" platform

* T1098.001: use new "azure-ad" platform

* Update T1098.001.yaml

* Update T1098.001.yaml

* Update T1098.001.yaml

Co-authored-by: piaconsigny <49986009+piaconsigny@users.noreply.github.com>
2021-07-08 11:23:05 -06:00
CircleCI Atomic Red Team doc generator 66bf3375ba Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:21:56 +00:00
CircleCI Atomic Red Team GUID generator 6036df88ac Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:21:50 +00:00
piaconsigny 62943530e9 T1110.001 azureadaccounts (#1482)
* T1110.001 azureadaccounts

* Update T1110.001.yaml

* Apply suggestion

* Remove typo

Co-authored-by: Clément Notin <cnotin@tenable.com>
2021-07-08 11:21:08 -06:00
Adam Mashinchi 8702d8e708 Update T1609.yaml 2021-07-07 14:52:38 -07:00
Adam Mashinchi 9d2dc1db4d Update T1552.007.yaml 2021-07-07 14:52:18 -07:00
Adam Mashinchi d99601f48a Update T1053.007.yaml 2021-07-07 14:49:06 -07:00
Adam Mashinchi c5b5f9ec70 Update Platform in T1611 to "containers"
Updating to reflect recent ATT&CK & Atomic-Red-Team "Platform" spec changes.
2021-07-07 11:15:45 -07:00
CircleCI Atomic Red Team doc generator 6f40c444af Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-07 17:38:50 +00:00
Clément Notin 1a4c4a97d2 Improve discoverability of "Active Directory" attacks (#1544) 2021-07-07 11:38:22 -06:00
CircleCI Atomic Red Team doc generator 412b05ad26 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-06 20:24:45 +00:00