Commit Graph

6538 Commits

Author SHA1 Message Date
Jorge Orchilles 19e2814e3c Adding System Language Discovery (#1906)
* Create T1553.005

* Create T1553.005.yaml

* Update T1553.005.yaml

* Update T1553.005.yaml

* Update T1553.005.yaml

* Update T1553.005.yaml

* Update T1553.005.yaml

* Update T1553.005.yaml

* Update T1553.005.yaml

* Updated T1553.005

* Merging

* Create T1614.001.yaml

* Update T1614.001.yaml

* Update T1614.001.yaml

* Update T1614.001.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-29 15:20:59 -06:00
Atomic Red Team doc generator a0c2520962 Generated docs from job=generate-docs branch=master [ci skip] 2022-04-29 21:19:24 +00:00
Atomic Red Team GUID generator 389f4d13f0 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-29 21:19:19 +00:00
tccontre 20e304c516 enumeration of active directory organization unit and root domain (#1907)
* Update T1112.yaml

* Update T1112.yaml

* typos

* Update T1087.002.yaml

* Update T1087.002.yaml

* Update T1087.002.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-29 15:18:53 -06:00
Atomic Red Team doc generator a082fb047a Generated docs from job=generate-docs branch=master [ci skip] 2022-04-29 21:06:05 +00:00
Atomic Red Team GUID generator 238ff5b80a Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-29 21:06:00 +00:00
Mohammed Hassan 8b57f31fc4 Update T1007.yaml (#1909)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-29 15:05:33 -06:00
Adam Mashinchi 988675b98b Merge pull request #1911 from redcanaryco/testest
Empty-Commit
2022-04-29 09:36:04 -07:00
d1vious c4b6a04182 Empty-Commit 2022-04-29 12:35:00 -04:00
Atomic Red Team doc generator 8c3b3277a6 Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:42:41 +00:00
frack113 531dc622ef T1555.003 Test 8 Add python prereq (#1883)
* Add python prereq

* typo fix

Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:42:11 -06:00
Atomic Red Team doc generator ab5e560865 Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:38:56 +00:00
Atomic Red Team GUID generator 3b7d1a9d19 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-28 01:38:52 +00:00
Rich5 da3488b3b7 Added Invoke-WMIExec Pass the Hash (#1896)
* Added Invoke-WMIExec Pass the Hash

* Update T1550.002.yaml

Updated with permanent link

Co-authored-by: Richard Kelley <richard.kelley@qomplx.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:38:25 -06:00
Atomic Red Team doc generator b194729422 Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:37:14 +00:00
Atomic Red Team GUID generator 22cfe0ad49 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-28 01:37:10 +00:00
Rich5 e51a12089e Added Crafting Active Directory silver tickets with mimikatz (#1897)
* Added Crafting Active Directory silver tickets with mimikatz

* Update T1558.002.yaml

Co-authored-by: Richard Kelley <richard.kelley@qomplx.com>
Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:36:42 -06:00
Atomic Red Team doc generator 667cfa7daa Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:34:38 +00:00
Atomic Red Team GUID generator 96fb67db9f Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-28 01:34:33 +00:00
Rich5 0edf9b8609 Added Injection SID-History with mimikatz (#1898)
* Added Injection SID-History with mimikatz

* Update T1134.005.yaml

Changed elevation_required to true

* remove guid

Co-authored-by: Richard Kelley <richard.kelley@qomplx.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:34:07 -06:00
Atomic Red Team doc generator dd97f407ad Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:22:28 +00:00
Atomic Red Team GUID generator 292fcfab98 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-28 01:22:24 +00:00
Rich5 53d54747ec Added Password Change on Directory Service Restore Mode (DSRM) Account (#1899)
* Added Password Change on Directory Service Restore Mode (DSRM) Account

* remove guid so unique one can be auto-assigned

Co-authored-by: Richard Kelley <richard.kelley@qomplx.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:21:55 -06:00
Atomic Red Team doc generator c7417ac40b Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:17:34 +00:00
Atomic Red Team GUID generator 04913e6441 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-28 01:17:28 +00:00
Leo Verlod 1e9f1a4c38 Adding T1539 Test 2 - Steal Chrome Cookies (#1901)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:17:03 -06:00
Atomic Red Team doc generator e406fe0a0f Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:16:26 +00:00
Jathan-McDaniel 4e7044e077 T1055.001 improvement (#1902)
Co-authored-by: McDaniel <jmcdan@NTI.local>
Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:15:57 -06:00
Atomic Red Team doc generator 724cb3f50d Generated docs from job=generate-docs branch=master [ci skip] 2022-04-28 01:14:49 +00:00
Atomic Red Team GUID generator b196333caf Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-28 01:14:45 +00:00
David McKennirey 0ddf5d32aa Add Atomic tests for disabling .NET ETW tracing (#1903)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-27 19:14:22 -06:00
Jose Enrique Hernandez d5dea0d03f minor adjustment to how workflows are triggered (#1905) 2022-04-27 19:13:33 -06:00
Atomic Red Team doc generator db4ca085fc Generated docs from job=generate-docs branch=master [ci skip] 2022-04-27 17:08:17 +00:00
Atomic Red Team GUID generator 94fb215b94 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-27 17:08:13 +00:00
zspadoni28 ac8cd38038 Adding T1562.006 Test Number 3 (#1900)
Adding test #3 to simulate the removal of the Powershell provider ETW telemetry source.
2022-04-27 11:07:43 -06:00
Atomic Red Team doc generator 7fa5d45acd Generated docs from job=generate-docs branch=master [ci skip] 2022-04-26 21:46:46 +00:00
Atomic Red Team GUID generator 00dd1f82a3 Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-26 21:46:41 +00:00
Adam Mashinchi 7ab002b355 Merge pull request #1892 from jovial7/patch-4
Add new test
2022-04-26 14:46:16 -07:00
Jose Enrique Hernandez 154ad8eeed Merge branch 'master' into patch-4 2022-04-26 17:43:18 -04:00
Atomic Red Team doc generator 059297cef5 Generated docs from job=generate-docs branch=master [ci skip] 2022-04-26 21:42:55 +00:00
Atomic Red Team GUID generator 30d17c913b Generate GUIDs from job=generate-docs branch=master [skip ci] 2022-04-26 21:42:51 +00:00
Adam Mashinchi 64ccef52c2 Merge pull request #1885 from jessefmoore/T1615jesseee
This is for the Challenge Bounty -Group Policy Discovery on Windows
2022-04-26 14:42:30 -07:00
Jose Enrique Hernandez 7ea76fd811 Merge branch 'master' into T1615jesseee 2022-04-26 17:37:30 -04:00
Jose Enrique Hernandez 6eec2463d2 Merge branch 'master' into patch-4 2022-04-26 17:35:20 -04:00
Jose Enrique Hernandez 5acc6a23a1 Merge pull request #1895 from redcanaryco/updating_badge
updating the badge
2022-04-26 17:32:04 -04:00
Jose Enrique Hernandez 8b7169cce6 Update README.md 2022-04-26 17:30:26 -04:00
d1vious c50a2009f7 updating the badge 2022-04-26 17:27:49 -04:00
Jose Enrique Hernandez e7ec519b53 Merge pull request #1894 from redcanaryco/dummy
Empty-Commit
2022-04-26 17:14:50 -04:00
d1vious 6173d5a1bf Empty-Commit 2022-04-26 17:12:23 -04:00
Atomic Red Team doc generator 83b0409004 Generated docs from job=generate-docs branch=master [ci skip] 2022-04-26 20:43:33 +00:00