Commit Graph

6538 Commits

Author SHA1 Message Date
api0cradle 92ab19d773 Created T1191 and T1183, added technique to T1060 2018-04-17 11:58:38 +02:00
Brian Beyer 55d9b37b22 start yamlizing a bunch of techniques 2018-04-17 00:13:12 -07:00
Ye Yint @ Rolan 71b51d6c47 update link based on Mitre April update 2018-04-16 18:07:57 +08:00
Ye Yint @ Rolan dd494582f6 updated based on Mitre April update 2018-04-16 18:02:46 +08:00
Ye Yint @ Rolan 3404c8b616 update based on Mitre April update 2018-04-16 18:01:06 +08:00
Ye Yint @ Rolan 0c20cf6541 updated link for Mitre April update 2018-04-16 17:21:05 +08:00
Ye Yint @ Rolan ccc9181745 update content for Mitre April update 2018-04-16 17:00:07 +08:00
Ye Yint @ Rolan 6fe6549019 update April TTP 2018-04-16 16:55:02 +08:00
Ye Yint @ Rolan 7c58727dff updated link for Mitre April update 2018-04-16 16:19:46 +08:00
Ye Yint @ Rolan 7ffbd63d28 updated link for April update 2018-04-16 16:08:36 +08:00
Ye Yint @ Rolan 4e228bdf9d updated link for April update 2018-04-16 16:05:34 +08:00
Ye Yint @ Rolan 253995967d updated link for April update 2018-04-16 16:05:01 +08:00
Ye Yint @ Rolan 960f294333 changed as april update 2018-04-16 15:22:25 +08:00
Ye Yint @ Rolan d7d25a182c added Initial access column 2018-04-16 14:26:35 +08:00
Ye Yint @ Rolan 5f848fe2c1 Merge pull request #1 from redcanaryco/master
update
2018-04-16 13:16:41 +08:00
caseysmithrc b300843c68 Merge pull request #115 from LeeHolmes/master
Adding starter implementation of Atomic Red Team Automation Framework…
2018-04-15 22:42:20 -06:00
Lee Holmes 9ddffd1b17 Adding starter implementation of Atomic Red Team Automation Framework, as well as Atomic Red Team testing framework 2018-04-15 17:54:49 -07:00
caseysmithrc fab50ebce7 Merge pull request #114 from infosecn1nja/patch-8
Update Disabling_Security_Tools.md
2018-04-13 07:33:05 -06:00
Rahmat Nurfauzi ec5af82e6e Update Disabling_Security_Tools.md 2018-04-13 20:29:22 +07:00
caseysmithrc 165607d242 Merge pull request #113 from redcanaryco/03082018
How to Contrib and Lateral Movement
2018-04-10 12:39:03 -06:00
Michael Haag 0bfdcfa480 Lateral Movement
+ PtH
+ RDP
2018-04-06 08:21:28 -04:00
caseysmithrc eced20df46 Merge pull request #108 from llandeilocymro/patch-1
Create psexec
2018-03-26 08:39:57 -06:00
caseysmithrc 5d0a121142 Merge pull request #111 from llandeilocymro/patch-3
psexec for lateral movement
2018-03-26 08:39:33 -06:00
llandeilocymro 5fd733a3ed psexec for lateral movement 2018-03-26 14:44:21 +01:00
Michael Haag e71d08b5a6 Merge pull request #109 from llandeilocymro/patch-2
cred dumping using the registry
2018-03-21 14:13:50 -04:00
Michael Haag e10be818ef Update Credential_Dumping.md 2018-03-21 14:13:10 -04:00
Michael Haag 6b3d5a1c69 Merge pull request #107 from ForensicITGuy/http-exfiltration
Added test to exfil data over HTTP
2018-03-20 12:33:45 -04:00
llandeilocymro c3bda067e2 cred dumping using the registry 2018-03-16 14:24:17 +00:00
llandeilocymro 1b3361896f Create psexec 2018-03-16 14:00:33 +00:00
ForensicITGuy e9f7a6c9ed Added test to exfil data over HTTP 2018-03-15 17:03:14 -05:00
caseysmithrc fdde68b5e7 Merge pull request #104 from ForensicITGuy/linux-root-ca
Added test to generate and trust root CA on Linux. Updated README.
2018-03-14 21:47:32 -06:00
caseysmithrc 2869a65cde Merge pull request #105 from ForensicITGuy/linux-file-deletion-etc
Added File Deletion, Data Compression/Encryption, Data splitting tests
2018-03-14 21:47:22 -06:00
caseysmithrc c5ed6a89f9 Update AtomicRedTeam.sct 2018-03-13 14:11:24 -06:00
Tony M Lambert 376512f6e2 Added File Deletion, Data Compression/Encryption, Data splitting tests 2018-03-12 01:32:55 -05:00
Tony M Lambert 779f2c71cc Added test to generate and trust root CA on Linux. Updated README. 2018-03-10 01:27:49 -06:00
caseysmithrc cbc36697f0 Merge pull request #103 from ForensicITGuy/disable-defenses
Disable defenses on Linux
2018-03-09 22:22:32 -07:00
Tony M Lambert 8346a7a1f5 Added tests for disable of firewall, syslog, Cb daemon, SELinux 2018-03-09 22:25:46 -06:00
Tony M Lambert 4f65330559 Added Remote File Copy tests on Linux and relevant README 2018-03-09 21:54:34 -06:00
Tony M Lambert 80a9487da3 Added test for timestomping on Linux with relevant README changes. 2018-03-09 19:51:46 -06:00
Michael Haag a023d346cb Contributions
How to contrib
2018-03-09 12:19:07 -06:00
caseysmithrc 82c57914fd Merge pull request #100 from ForensicITGuy/master
Added Hidden Files and Directories checks for Linux
2018-03-08 22:57:25 -07:00
Tony M Lambert 8b8d6059ee Added Hidden Files and Directories checks for Linux 2018-03-08 23:52:30 -06:00
caseysmithrc 4874dbc78c Merge pull request #99 from redcanaryco/03082018
Technique Adds
2018-03-08 13:31:55 -07:00
Michael Haag 27cb5a75c6 Fix
updated
2018-03-08 14:28:13 -06:00
Michael Haag 8ba1dc8a19 Technique Adds
Private Keys
- Find them

DDE
- Reference: https://sensepost.com/blog/2017/macro-less-code-exec-in-msword/

Data Staged
2018-03-08 14:26:18 -06:00
Michael Haag a6134b19c0 Techniques and Readme
Technique: Hidden Files and Directories

Technique: Logon Scripts
- Source: https://github.com/NextronSystems/APTSimulator/blob/1c9048e834f0adabd18c8871d587fda42315575b/test-sets/persistence/userinit-mpr-logonscript.bat

Readme updates
2018-03-08 08:11:24 -06:00
Michael Haag 5078248ca1 Merge pull request #95 from TacoRocket/master
Added Screen Capture from Keylogger to Collection
2018-03-06 09:20:01 -06:00
caseysmithrc c3377e74d6 Merge pull request #86 from ahogue-atlassian/master
Add Custom C2 Protocol - Bitbucket Snippets
2018-03-06 07:45:05 -07:00
Michael Haag e6622d0021 Updated title 2018-03-06 08:43:51 -06:00
ahogue-atlassian 3aa4c528d9 Merge branch 'master' into master 2018-03-06 09:05:52 +11:00