Commit Graph

6538 Commits

Author SHA1 Message Date
Dan b1f18f38ff Update T1135-2 (#2021)
Run smbstatus with sudo

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-07-01 20:42:09 -06:00
Atomic Red Team doc generator 266cafe4ae Generated docs from job=generate-docs branch=master [ci skip] 2022-07-02 02:37:34 +00:00
Atomic Red Team GUID generator 21dc92261d Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-07-02 02:37:28 +00:00
frack113 857e9eaf75 Add simple test (#2015)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-07-01 20:37:00 -06:00
Atomic Red Team doc generator 2411cb6cef Generated docs from job=generate-docs branch=master [ci skip] 2022-07-02 02:35:19 +00:00
Dan 2bcf9a713f Update T1087.002-3 (#2019)
Use COMPUTERNAME variable for command prompt.

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-07-01 20:34:51 -06:00
Atomic Red Team doc generator 1324d0f434 Generated docs from job=generate-docs branch=master [ci skip] 2022-07-02 02:25:49 +00:00
Atomic Red Team GUID generator 39edfb5296 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-07-02 02:25:44 +00:00
zspadoni28 20b438d4bd Adding T1219-8 | NetSupport - RAT Execution (#2017)
* Update T1219.yaml with NetSupport RAT Execution

This test is designed to install and execute the NetSupport tool that is capable of RAT execution.

* Update T1219.yaml
2022-07-01 20:25:13 -06:00
Brendan Malone 9307edbf71 Update chown.c 2022-06-30 13:39:29 -05:00
Leo Verlod 9f7a456f9f Adding T1082 Test - Azure Security Scan with SkyArk 2022-06-29 00:09:34 -05:00
Brendan Malone 875845f669 Add files via upload 2022-06-27 15:02:21 -05:00
Brendan Malone 0e5861eee3 Added chown script 2022-06-27 15:01:59 -05:00
Brendan Malone e0c9dad4cf Rename atomics/T1222.002/T1222.002.c to atomics/T1222.002/src/T1222.002.c 2022-06-27 10:46:24 -05:00
Brendan Malone 3b34c838c6 Add files via upload 2022-06-27 10:45:39 -05:00
Brendan Malone 71ba8e9676 Added Chmod through c script test 2022-06-27 10:45:14 -05:00
Leo Verlod 673b63af0b Adding T1530 Test 2 2022-06-26 03:08:33 -05:00
Atomic Red Team doc generator 96f7ca5f9b Generated docs from job=generate-docs branch=master [ci skip] 2022-06-26 00:13:54 +00:00
Atomic Red Team GUID generator d0d95fe8ad Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-06-26 00:13:49 +00:00
Jose Enrique Hernandez a1b8b67669 Merge pull request #1994 from ruyek-git/patch-1
Python pty module and spawn function used to spawn sh or bash
2022-06-25 20:13:24 -04:00
Jose Enrique Hernandez 15ce614164 Merge branch 'master' into patch-1 2022-06-25 20:12:37 -04:00
Atomic Red Team doc generator 71bedf4947 Generated docs from job=generate-docs branch=master [ci skip] 2022-06-26 00:11:09 +00:00
Jose Enrique Hernandez 808c3ca081 Merge pull request #2012 from RoundBunny/T1027
Updated T1027 i0 with cleanup and non-builtin command
2022-06-25 20:10:35 -04:00
Jose Enrique Hernandez 53f16a761c Merge branch 'master' into T1027 2022-06-25 20:09:23 -04:00
ruyek-git c007d9c473 Update T1059.006.yaml
indentation adjusted for line #158
2022-06-25 18:53:22 -05:00
Jose Enrique Hernandez 317c943f4c Merge branch 'master' into patch-1 2022-06-25 18:29:42 -04:00
Atomic Red Team doc generator 566c6d6d28 Generated docs from job=generate-docs branch=master [ci skip] 2022-06-24 03:59:02 +00:00
Dan 9898bb9ecb Update T1078.003-1 (#2013)
* Update T1078.003-1

Make password an input argument for Test 1

* try to make the default password work in more environments

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-06-23 21:58:27 -06:00
Atomic Red Team doc generator 0d352c3c8e Generated docs from job=generate-docs branch=master [ci skip] 2022-06-23 19:46:46 +00:00
Atomic Red Team GUID generator 7312259b59 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-06-23 19:46:40 +00:00
tccontre 26dda89f12 disabling several Windows Notifications and Allow RDP remote assistance Features (#2011)
* Update T1112.yaml

* Update T1112.yaml

* typos

* Update T1087.002.yaml

* Update T1087.002.yaml

* Update T1087.002.yaml

* Add files via upload

* Update T1053_05_SCTASK_HIDDEN_ATTRIB.xml

* Update T1053.005.yaml

* Update T1053.005.yaml

* Update T1087.002.yaml

* Update T1087.002.yaml

* Update T1112.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-06-23 13:46:11 -06:00
Brendan Malone 1497723728 Updated T1027 i0 with cleanup and non-builtin command
We were having a hard time detecting this one because echo is a built-in command. In addition, this test has no cleanup. Added both cleanup and a bash/sh command
2022-06-23 14:10:17 -05:00
Atomic Red Team doc generator b73cf1d197 Generated docs from job=generate-docs branch=master [ci skip] 2022-06-23 04:08:45 +00:00
Atomic Red Team GUID generator f0b856a013 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-06-23 04:08:39 +00:00
Jacques Decarie a846bab9b2 T1546.009 (#2009)
* attempt to stop service first, in case its already running

* adding T1546.009

* correct T number

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-06-22 22:08:15 -06:00
Atomic Red Team doc generator 436a980bd2 Generated docs from job=generate-docs branch=master [ci skip] 2022-06-23 04:02:16 +00:00
Dan bae573c815 Update T1083-1 (#2008)
Added a cleanup command to delete the file created during test execution.  Updated the file written to during test execution to be specified as an input argument.

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-06-22 22:01:42 -06:00
Atomic Red Team doc generator 38b85ead3f Generated docs from job=generate-docs branch=master [ci skip] 2022-06-23 03:56:28 +00:00
packetzero dd5674f066 T1543.004 cleanup file created by launch daemon (#2010) 2022-06-22 21:56:00 -06:00
Atomic Red Team doc generator e056ac4633 Generated docs from job=generate-docs branch=master [ci skip] 2022-06-22 19:15:42 +00:00
Atomic Red Team GUID generator e7167fffaf Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-06-22 19:15:36 +00:00
Bhavin Patel fe2b4be15f Merge pull request #1995 from Leomon5/patch-1
Adding T1530 Test 1 - Enumerate Azure Blobs with MicroBurst
2022-06-22 12:15:03 -07:00
Leo Verlod 449ddbf266 Updating test name and supported platform 2022-06-21 20:34:23 -05:00
ruyek-git ad5cdce233 Update T1059.006.yaml 2022-06-21 17:57:24 -05:00
ruyek-git 8e8ae44bc5 Update T1059.006.yaml
spaces adjusted. exit cmd added to avoid timeout if it works.
2022-06-21 17:43:42 -05:00
Bhavin Patel 97dbd15567 Merge branch 'master' into patch-1 2022-06-21 15:30:50 -07:00
Jose Enrique Hernandez 7080d1c962 Merge branch 'master' into patch-1 2022-06-21 14:25:51 -04:00
Atomic Red Team doc generator 60a6fea2b1 Generated docs from job=generate-docs branch=master [ci skip] 2022-06-21 17:46:20 +00:00
Atomic Red Team GUID generator eb5c6221dd Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-06-21 17:46:13 +00:00
JrOrOneEquals1 c573365bb5 New test using TruffleSnout.exe/typo (#2002)
* Update README.md

* Add files via upload

* Create idk

* Delete TruffleSnout.exe

* Delete idk

* Create a

* Upload TruffleSnout.exe

* Delete a

* Add new test using TruffleSnout.exe

* Fix #s on commands, change download url

* Update T1482.yaml

* Change default to %userdomain%

* Put % default value in quotes

* Delete TruffleSnout.exe

* Update T1482.yaml
2022-06-21 11:45:37 -06:00