Commit Graph

6538 Commits

Author SHA1 Message Date
well123cs 1ca680d0d5 Update T1612.yaml 2023-03-17 16:58:50 -07:00
well123cs e327248278 Add files via upload 2023-03-17 15:21:40 -07:00
Atomic Red Team doc generator c967af1060 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-17 20:40:08 +00:00
Atomic Red Team GUID generator cc36afc188 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-03-17 20:39:52 +00:00
Bhavin Patel 0496bcb379 Merge pull request #2362 from m4nbat/gk-atomic-red-team-T1531-Account-Deletion
Gk atomic red team t1531 account deletion
2023-03-17 15:38:50 -05:00
Bhavin Patel bd9dde39e2 Merge branch 'master' into gk-atomic-red-team-T1531-Account-Deletion 2023-03-17 15:37:18 -05:00
Atomic Red Team doc generator 8ec8bb8d24 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-17 20:01:43 +00:00
Paul b46cedacdd Merge pull request #2374 from redcanaryco/T1033-Cleanup-Fix
Fix-Cleanup-Command
2023-03-17 16:00:11 -04:00
Paul 198b2c3fcc Merge branch 'master' into T1033-Cleanup-Fix 2023-03-17 15:58:40 -04:00
Atomic Red Team doc generator aaf94f9b37 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-17 19:58:12 +00:00
Atomic Red Team GUID generator d9ad3781d6 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-03-17 19:57:57 +00:00
Paul db6e360cc3 Merge branch 'master' into T1033-Cleanup-Fix 2023-03-17 15:57:18 -04:00
Paul 8e27dbe2b1 Merge pull request #2365 from iai-rsa/T1012
update T1012 with more commands
2023-03-17 15:56:57 -04:00
Paul ae0f02b079 Merge branch 'master' into T1012 2023-03-17 15:55:29 -04:00
Michael Haag 26aa690d68 Update T1012.yaml
fix guid
2023-03-17 13:53:52 -06:00
Jose Enrique Hernandez 16636cda60 Merge branch 'master' into T1059.004_IV 2023-03-17 15:48:16 -04:00
Atomic Red Team doc generator 96d11e0592 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-17 19:48:14 +00:00
Atomic Red Team GUID generator 07deaa02b1 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-03-17 19:47:58 +00:00
Jose Enrique Hernandez 7356f2eb55 Merge pull request #2336 from biot-2131/T1110.001_II
T1110.001 updated two tests
2023-03-17 15:46:56 -04:00
Jose Enrique Hernandez 278a7d5a6d Merge branch 'master' into T1110.001_II 2023-03-17 15:43:41 -04:00
Jose Enrique Hernandez a644221a85 Merge branch 'master' into patch-2 2023-03-17 15:42:37 -04:00
Paul 8815d0821f Merge branch 'master' into T1012 2023-03-17 15:41:46 -04:00
Carrie Roberts 9c6e2bae53 Merge branch 'master' into T1033-Cleanup-Fix 2023-03-17 13:28:25 -06:00
Atomic Red Team doc generator 27770715fb Generated docs from job=generate-docs branch=master [ci skip] 2023-03-17 19:20:24 +00:00
Bhavin Patel 7f8676c6b9 Merge pull request #2364 from cnotin/pr-fix-upn-confusion
T098: accept UserPrincipalName for the "user_principal_name" argument
2023-03-17 14:18:53 -05:00
Bhavin Patel d87f86a4d6 Merge branch 'master' into pr-fix-upn-confusion 2023-03-17 14:11:42 -05:00
Atomic Red Team doc generator c3675964f8 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-17 19:00:35 +00:00
Atomic Red Team GUID generator fa1e708682 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-03-17 19:00:19 +00:00
Jose Enrique Hernandez 0f79569e2d Merge pull request #2321 from D4rkCiph3r/T1078.003
Added 3 new tests T1078.003 - macOS
2023-03-17 14:59:16 -04:00
Jose Enrique Hernandez 29aa3f07bf Merge branch 'master' into T1078.003 2023-03-17 12:38:36 -04:00
Jose Enrique Hernandez 4ca92ab6b6 Merge branch 'master' into patch-1 2023-03-17 11:29:18 -04:00
Burning_PM 67afbfe15c Fix-Cleanup-Command
Fix the cleanup command to pass the output_path input argument instead of being hardcoded.
2023-03-17 06:53:35 -07:00
Gavin Knapp 171d9d5e72 Merge branch 'master' into gk-atomic-red-team-T1531-Account-Deletion 2023-03-17 08:34:04 +00:00
Atomic Red Team doc generator 8025353c3d Generated docs from job=generate-docs branch=master [ci skip] 2023-03-16 23:41:15 +00:00
Atomic Red Team GUID generator d62766548b Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-03-16 23:40:55 +00:00
Paul 73a144caa6 T1033-whoami-simplification (#2370)
* Variation on system/user discovery

Slight variation on Test 1: System Owner/User Discovery. This is meant to be a stripped down version.

* Update T1033.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-03-16 17:39:46 -06:00
Atomic Red Team doc generator 077f0ac288 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-16 23:36:29 +00:00
Atomic Red Team GUID generator 824eb46e08 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-03-16 23:36:12 +00:00
Carrie Roberts 011e512d29 add Cobalt Strike named pipe atomics (#2372) 2023-03-16 17:35:10 -06:00
hg8064 9cbcd8977c update T1562.004 with more commands 2023-03-16 17:49:53 +01:00
Atomic Red Team doc generator 809970561a Generated docs from job=generate-docs branch=master [ci skip] 2023-03-16 15:51:28 +00:00
Carrie Roberts 9fed5b2315 remove unused input arg (#2368)
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2023-03-16 09:50:15 -06:00
Atomic Red Team doc generator 7db6b229bd Generated docs from job=generate-docs branch=master [ci skip] 2023-03-16 15:48:11 +00:00
Carrie Roberts 6a7bdf14d9 remove unused input arg (#2367)
Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2023-03-16 09:47:23 -06:00
Atomic Red Team doc generator 535c693a65 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-16 15:44:49 +00:00
Carrie Roberts 4d272cdcdc remove unused inputargs (#2366) 2023-03-16 09:44:03 -06:00
hg8064 cc251318dc update T1012 with more commands 2023-03-15 20:10:31 +01:00
Clément Notin efd6dbb465 T098: accept UserPrincipalName for the "user_principal_name" argument
In Azure AD a "user principal name" can be interpreted as the "name of a principal of type user"
or as the "UserPrincipalName (UPN)" user attribute!
But most people will expect the second meaning. Which is confusing since this test actually expects to see
the user display name in this attribute.

I think there was a confusion with the sibling test which is for "service principal",
so for which the argument to designate it by name is "service_principal_name".

With this change, there is no regression while being compatible with people passing a UPN to this argument.
2023-03-15 18:25:11 +01:00
Gavin Knapp 92c180bf43 Merge branch 'redcanaryco:master' into gk-atomic-red-team-T1531-Account-Deletion 2023-03-14 07:53:42 +00:00
Atomic Red Team doc generator 159dda49d8 Generated docs from job=generate-docs branch=master [ci skip] 2023-03-14 00:45:40 +00:00