Commit Graph

6538 Commits

Author SHA1 Message Date
Carrie Roberts 4133575f2e use command prompt (#2559)
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2023-10-10 11:03:10 -06:00
Atomic Red Team doc generator 4b58fa4f25 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-10 16:05:30 +00:00
Carrie Roberts e8d26acbc7 use cmd.exe syntax for temp dir (#2558)
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2023-10-10 10:04:16 -06:00
Atomic Red Team doc generator 3625d11dd4 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-10 15:57:18 +00:00
Carrie Roberts 07da073a66 fix command (#2557) 2023-10-10 09:55:20 -06:00
Atomic Red Team doc generator 04e487c182 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:26:58 +00:00
Carrie Roberts 62f83972c5 use external payloads directory (#2554)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-07 15:25:51 -04:00
Atomic Red Team doc generator a08834a85c Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:21:34 +00:00
Carrie Roberts 076d228371 quote path (#2555)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-07 15:20:38 -04:00
Atomic Red Team doc generator c0a77d2d6d Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:10:44 +00:00
Carrie Roberts 8666118b4b no prompt for confirmation (#2553)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-07 15:09:32 -04:00
Atomic Red Team doc generator 008fc61040 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-07 19:07:22 +00:00
Atomic Red Team GUID generator 9fcde0a924 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-07 19:07:01 +00:00
Carrie Roberts 72585c9dd7 fix typo (#2556) 2023-10-07 15:05:53 -04:00
publish bot 6ac219560e updating atomics count in README.md [ci skip] 2023-10-03 21:23:40 +00:00
Jonathan 81368acdd7 Add T1056.002 Gui Input Capture macOS test (#2531)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-03 17:22:55 -04:00
Atomic Red Team doc generator 5e4a0cea17 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-03 17:49:04 +00:00
Atomic Red Team GUID generator 34e755969e Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-03 17:48:44 +00:00
Swachchhanda Shrawan Poudel 9026f98900 Added few new tests for T1518.001 and also rdrleakdiag.exe test accessing lsass (#2550)
* Added lolbin rdrleakdiag support for lsass dumping and some Security Software Discovery tests

* Changes done as suggested

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-10-03 11:48:00 -06:00
Atomic Red Team doc generator a007c274f6 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-03 17:39:50 +00:00
Carrie Roberts d667fffea2 correct url (#2552)
* correct url

* Update T1027.yaml
2023-10-03 11:38:37 -06:00
Atomic Red Team doc generator 302abbb7b7 Generated docs from job=generate-docs branch=master [ci skip] 2023-10-03 11:06:39 +00:00
Atomic Red Team GUID generator 4b343f18ab Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-03 11:06:21 +00:00
socketz 99e7f006f1 T1055.011 - Process Injection: Extra Window Memory Injection (#2539)
* Updated .gitignore with more files to be ignored

* Working T1055.011 x64 payload. WIP x86

* Fixed a bug executing from Invoke-AtomicTest. x86 WIP

* Update T1055.011.yaml

Removed autogenerated_guid

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
2023-10-03 07:05:41 -04:00
publish bot bedfdfd91a updating atomics count in README.md [ci skip] 2023-10-03 01:05:05 +00:00
dependabot[bot] ebf17ef2bc Bump urllib3 from 2.0.4 to 2.0.6 (#2551)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.0.4 to 2.0.6.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/2.0.4...2.0.6)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 19:04:14 -06:00
Atomic Red Team doc generator b2204555cf Generated docs from job=generate-docs branch=master [ci skip] 2023-10-02 20:45:35 +00:00
Atomic Red Team GUID generator 19c71c2a40 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-02 20:45:17 +00:00
Mohana Shankar D 3397666c5c New Atomic Test: PromptOnSecureDesktop (#2549)
* New Atomic Test: PromptOnSecureDesktop

* Update T1548.002.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-10-02 14:44:36 -06:00
traceflow 30947260a6 adding test simulating DarkGate malware writing script to file from cmd (#2548)
* adding test simulating DarkGate malware writing script to file from cmd

* adding test simulating DarkGate malware writing script to file from cmd

* updating atomics count in README.md [ci skip]

---------

Co-authored-by: publish bot <opensource@redcanary.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:52:48 -06:00
Atomic Red Team doc generator d387c3e718 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:51:00 +00:00
Atomic Red Team GUID generator 971f54bdf9 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-29 14:50:42 +00:00
Swachchhanda Shrawan Poudel 247349eb5c Added new tests for techniques T1082 and T1070 (#2547)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:50:02 -06:00
Atomic Red Team doc generator 9bf809338a Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:45:43 +00:00
Atomic Red Team GUID generator 33aa1e0df2 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-29 14:45:20 +00:00
Tuutaans 2dc70561dd Provlaunch.exe Executes Arbitrary Command via Registry Key (#2546)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:44:32 -06:00
Atomic Red Team doc generator ccdf46f389 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:41:30 +00:00
Antonio Piazza f68822b349 Added ExternalPayloads directory (#2545)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

* Update T1110.004.yaml

Added Powershell Command to creat ExternalPayloads dir for the second prereq for procedure 4852c630-87a9-409b-bb5e-5dc12c9ebcde.

* Update T1110.001.yaml

Added ExrernalPayload directory creation PowerShell command for procedure 59dbeb1a-79a7-4c2a-baf4-46d0f4c761c4
prereq 2

* Added ExternalPayloads Dir

Added Powershell command to create new ExternalPayloads dir for procedure fad04df1-5229-4185-b016-fb6010cd87ac

* Add ExternalPayloads Dir

Added PowerShell Command to create new ExternalPayloads directory for procedure c6f25ec3-6475-47a9-b75d-09ac593c5ecb

* Added prereq download directories

Added powershell command to create prereq download directories for procedure 6f2c5c87-a4d5-4898-9bd1-47a55ecaf1dd

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:40:27 -06:00
zaicurity 273e3c0fb7 Fix T1083-6 DirLister PreReqs (#2541)
* Fix T1083-6 DirLister PreReqs

A quote symbol in the get_prereq_command was wrong which caused the directory name to include "-Force". Due to this the script failed.

* updating atomics count in README.md [ci skip]

---------

Co-authored-by: publish bot <opensource@redcanary.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:35:42 -06:00
Atomic Red Team doc generator dc194fadf2 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:31:57 +00:00
Antonio Piazza b524d93bad New ExternalPayloads dir creation (#2544)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

* Update T1110.004.yaml

Added Powershell Command to creat ExternalPayloads dir for the second prereq for procedure 4852c630-87a9-409b-bb5e-5dc12c9ebcde.

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:31:00 -06:00
publish bot b223a8e79b updating atomics count in README.md [ci skip] 2023-09-25 20:29:14 +00:00
dependabot[bot] ba4ba09d39 Bump jsonschema from 4.19.0 to 4.19.1 (#2540)
Bumps [jsonschema](https://github.com/python-jsonschema/jsonschema) from 4.19.0 to 4.19.1.
- [Release notes](https://github.com/python-jsonschema/jsonschema/releases)
- [Changelog](https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/python-jsonschema/jsonschema/compare/v4.19.0...v4.19.1)

---
updated-dependencies:
- dependency-name: jsonschema
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:28:32 -06:00
Atomic Red Team doc generator 098dfbfe5b Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:27:05 +00:00
Antonio Piazza a301206811 Download Directory creation (#2543)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:26:08 -06:00
Atomic Red Team doc generator d146373e1f Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:24:07 +00:00
Antonio Piazza 7c61ce15f0 Update T1036.yaml (#2542)
Added ExternalPayloads directory creation via powershell command for procedure 4449c89b-ec82-43a4-89c1-91e2f1abeecc
2023-09-25 14:22:53 -06:00
Atomic Red Team doc generator 81692e20cd Generated docs from job=generate-docs branch=master [ci skip] 2023-09-23 03:44:15 +00:00
Carrie Roberts fc3bfecda2 use ExternalPayloads folder (#2538) 2023-09-22 23:43:06 -04:00
Atomic Red Team doc generator 78204c6965 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-22 21:07:21 +00:00