Commit Graph

5173 Commits

Author SHA1 Message Date
skandler b1292579d2 Update T1552.yaml (#2829)
added an atomic which searches for password strings in powershell history file

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-04 12:05:04 -05:00
Atomic Red Team doc generator 3fd025b45c Generated docs from job=generate-docs branch=master [ci skip] 2024-07-04 17:03:39 +00:00
skandler e916ce5772 Update T1486.yaml (#2828)
Added an atomic for dropping 100 files with .akira ending and random content and dropping the akira ransomnote
2024-07-04 12:02:23 -05:00
Atomic Red Team doc generator 7103d7427f Generated docs from job=generate-docs branch=master [ci skip] 2024-07-03 22:32:13 +00:00
Phil Hagen fd399bb6ed fix nesting and remove empty entries (#2825)
* fix nesting and remove empty entries

* missed an indent correction

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-03 16:31:05 -06:00
Atomic Red Team doc generator 87b5a285ca Generated docs from job=generate-docs branch=master [ci skip] 2024-07-03 22:29:55 +00:00
Štěpán Bendl 4630d707be Remove dependencies from T1070.006's Modify file timestamps using reference file (#2824) 2024-07-03 16:28:42 -06:00
Atomic Red Team doc generator a96f4212a5 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-03 01:18:53 +00:00
Markus 158728fab4 T1048.003: Fix DNS exfiltration command escaping (#2823)
Co-authored-by: Markus Schader <markus.schader@worldline.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-02 20:17:44 -05:00
Atomic Red Team doc generator 4fa2ba6608 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-03 01:11:11 +00:00
Prakash22-k 137fb9f7e3 Update T1202.yaml (#2820)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-02 20:09:55 -05:00
Atomic Red Team doc generator 6e6af49776 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-03 01:08:20 +00:00
soumyadeep09 9d56cff212 T1070.006 Event Log Manipulations- Time slipping via Powershell (#2819)
* Update T1070.006.yaml

* Update T1070.006.yaml

* Update T1070.006.yaml

* Update T1070.006.yaml

* add cleanup commands

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-02 20:07:14 -05:00
Atomic Red Team doc generator adb1f314bf Generated docs from job=generate-docs branch=master [ci skip] 2024-07-03 00:32:46 +00:00
Br3akp0int a3014001a9 ShrinkLocker PIN,TPM Bitlocker Registry Modification (#2817)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-02 19:31:31 -05:00
Atomic Red Team doc generator 75a7a106ce Generated docs from job=generate-docs branch=master [ci skip] 2024-07-03 00:26:33 +00:00
Prakash22-k 9d5c56fac7 Update T1218.011.yaml (#2813)
Details:
Adding new atomic Test for Windows - Rundll32 execute payload by calling RouteTheCall

Testing:
Performed the Testing Atomic Lab

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-02 19:25:10 -05:00
Atomic Red Team doc generator abb837bcfe Generated docs from job=generate-docs branch=master [ci skip] 2024-06-28 23:08:09 +00:00
Enes 647c26323f Create T1652 folder and yaml file (#2808)
* Create T1652

Adding a new folder so that I can add a YAML file for a new test.

* Delete atomics/T1652

Restarting

* Create T1652.yaml

Created a folder and new a new YAML file.

* Update T1652.yaml

Added more verbosity and details to t1652.

* Update T1082.yaml

Atomic Test #28 - Driver Enumeration using DriverQuery

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-06-28 18:06:32 -05:00
Atomic Red Team doc generator 05d3123aa5 Generated docs from job=generate-docs branch=master [ci skip] 2024-06-18 18:41:54 +00:00
nish221b-bs b84afa7c76 Update T1112.yaml (#2809)
Added new Atomic "Flush ShimCache"

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-06-18 13:40:42 -05:00
Atomic Red Team doc generator f8df955af0 Generated docs from job=generate-docs branch=master [ci skip] 2024-06-18 18:10:56 +00:00
abhijose09 f205476bf7 Update T1046.yaml (#2802)
added new test

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-06-18 13:09:50 -05:00
Atomic Red Team doc generator 0658d14d1d Generated docs from job=generate-docs branch=master [ci skip] 2024-06-13 22:08:58 +00:00
Alphonsa George 1cb761c5a0 Modified the Prereq_command of Test Unload Sysmon Filter Driver (#2807)
* Modified the Prereq_command of Test Unload Sysmon Filter Driver

* modified typo on the description

---------

Co-authored-by: alphonsa-01 <NA>
2024-06-13 17:07:09 -05:00
Atomic Red Team doc generator 1e3b63fbaf Generated docs from job=generate-docs branch=master [ci skip] 2024-06-04 14:50:36 +00:00
NeuralGlitch 30b73d06bf Update to T1105 with New Atomic Test (#2792)
* Adding a sample zip file to help with atomic test

* Update T1105.yaml

* Update T1105.yaml

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-06-04 09:49:22 -05:00
Atomic Red Team doc generator 430b2ac270 Generated docs from job=generate-docs branch=master [ci skip] 2024-06-04 14:41:09 +00:00
Mohana Shankar D c2bcb1c2a6 Update T1057.yaml (#2791)
New Process discovery atomic using PC hunter

Co-authored-by: Hare Sudhan <code@0x6c.dev>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-06-04 09:39:56 -05:00
Phil Hagen 4b63cc604e Change ISO8859-1 to UTF-8 on included MD file (#2798)
* fix jinja2 syntax

* fix LinkById syntax

* further syntax correction for LinkById instances

* change encoding to UTF-8 to satisfy subsequent build processes
2024-06-03 17:38:44 -04:00
Phil Hagen 16ed461ee4 Fix LinkById syntax (#2794)
* fix jinja2 syntax

* fix LinkById syntax

* further syntax correction for LinkById instances
2024-06-03 12:46:19 -04:00
Atomic Red Team doc generator 65ef96a69d Generated docs from job=generate-docs branch=master [ci skip] 2024-06-03 11:09:33 +00:00
Carrie Roberts 8537ebde3c fix undefined filename (#2790)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2024-06-03 07:08:11 -04:00
Atomic Red Team doc generator fa4273ccd9 Generated docs from job=generate-docs branch=master [ci skip] 2024-05-31 14:19:47 +00:00
Phil Hagen f4382cf14c fix jinja2 syntax (#2793) 2024-05-31 10:18:39 -04:00
Atomic Red Team doc generator c816622770 Generated docs from job=generate-docs branch=master [ci skip] 2024-05-29 23:42:13 +00:00
NeuralGlitch fbe8663f49 Update T1562.001.yaml (#2788)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-05-29 18:40:55 -05:00
nish221b-bs 5175bbc392 Update T1112.yaml (#2785)
* Update T1112.yaml

Adding a new atomic test for registry modification for shadow key in terminal services

* Update T1112.yaml

Make reference a link, remove empty guid

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-05-29 18:39:11 -05:00
Atomic Red Team doc generator 25fdb321ee Generated docs from job=generate-docs branch=master [ci skip] 2024-05-16 01:42:23 +00:00
Pavan R Patil c26905e768 Added Splashstop streamer to T1219 (#2781)
* Added Splashstop streamer to T1219

* Fix YAML indent

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
2024-05-15 20:41:05 -05:00
Atomic Red Team doc generator e855218dba Generated docs from job=generate-docs branch=master [ci skip] 2024-05-15 00:55:00 +00:00
abhijose09 efa3370b62 Update T1569.002.yaml (#2776)
* Update T1569.002.yaml

Added new test Modifying ACL of Service Control Manager via SDET

* correction

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2024-05-14 20:53:45 -04:00
Atomic Red Team doc generator 7bf6eaa80d Generated docs from job=generate-docs branch=master [ci skip] 2024-05-15 00:52:20 +00:00
Tessa Georgen 5d816a1ddb remove empty cleanup and add an auto_generated_guid (#2779)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2024-05-14 20:51:06 -04:00
Atomic Red Team doc generator 9c842daeb3 Generated docs from job=generate-docs branch=master [ci skip] 2024-05-15 00:48:54 +00:00
Hare Sudhan 5f71a665e2 Fix T1219 test (#2780) 2024-05-14 19:41:14 -05:00
abhijose09 5f866ca451 Update T1112.yaml (#2774)
* Update T1112.yaml

Add new test Disable Windows Prefetch Through Registry

* fix spacing

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-05-10 13:36:54 -05:00
johnk3r 56b0e29923 New - T1553.006 (#2775)
* Create T1553.006.md

* Create T1553.006.yaml

* Update T1553.006.yaml

* Update T1553.006.md

* Update T1553.006.md

* Update T1553.006.md

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-05-10 13:34:29 -05:00
Leo Verlod 1c452cbafb Adding Netscan test to T1018 (#2767)
* Adding Netscan test to T1018

* Fixing typo in Netscan test description

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-05-10 13:00:34 -05:00
Leo Verlod b2658be590 Update T1219.yaml (#2763)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-05-10 12:54:10 -05:00